Package Health

techdivision/import-attribute

This is a healthy, mature release with more than nine years of history, 85 releases, five releases in the last 12 months, stable versioning, current repository activity, tests, changelog, a complete-looking source tree, and clear MIT licensing. The main concerns are that recent repository work is concentrated in one contributor, no security scanning or security policy was observed, and the single workflow does not declare top-level token permissions; these are meaningful hygiene and resilience gaps but are not evidence of abandonment, especially given organization ownership, a recent push, and ongoing release activity.

Latest 23.3.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access, which is a mild publishing-resilience concern; however, the repository is owned by the techdivision organization and observed release activity is ongoing.

Repo bus factorcaution

All 4 recent commits came from one contributor, creating a genuine contributor-concentration and continuity risk. Organization ownership provides some compensating handoff capacity, but no second recent contributor is shown.

Repo toolingcaution

Composer and Robo are used as build tools, but no security scanning tools were detected; the build setup is present while automated security coverage is a hygiene gap.

Security policycaution

No repository security policy was found, reducing transparency about vulnerability reporting and response procedures. This is a hygiene concern, not evidence that the package is unsafe.

Token permissionscaution

The single workflow lacks top-level token permissions declarations. Although no top-level write permissions were observed, explicitly limiting permissions would provide stronger CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tim Wagner

Direct Dependencies

DependencyLast ReleaseScore
techdivision/import
Version ^18.2
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform