Package Health

tenqz/shortify

The repository has been inactive for about 17 months, with no recent commits or releases. Tests, a clear README, a stable version, and minimal runtime dependencies provide useful structure, but missing security tooling and loosely pinned workflow actions add hygiene concerns.

Latest v1.1.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitydanger

The repository has had zero commits and zero active maintainers in the last three months, consistent with the last push being about 17 months ago. No provided maintenance signal compensates for this inactivity.

Release historycaution

Only three releases exist, all within an approximately three-week period, and there have been no releases in the last 12 months. This suggests a small or inactive project rather than an established release cadence.

Repo popularitycaution

The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of broad community adoption or review.

Security policycaution

The linked repository has no security policy and no security-scanning tools. For a small URL-shortening library this is a transparency and maintenance gap, though not a severe risk by itself.

Workflow auditcaution

Both workflows were analyzed without detected dangerous findings, and one uses read-only permissions, but all 4 referenced actions are unpinned. That leaves avoidable workflow reproducibility and update risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Oleg Patsay

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform