Package Health

the-shit/music

A single active contributor limits handoff capacity, and the project has no published security policy. Stable releases, tests, documentation, and MIT licensing provide useful counterweight.

Latest v1.2.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo bus factorcaution

All six recent commits came from one contributor, leaving maintenance and review capacity concentrated in a single person.

Repo commit activitycaution

Six commits in the last three months show ongoing work, but activity is modest and comes from only one active maintainer.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Workflow auditcaution

All 11 analyzed action references are unpinned, and the audit found a high-confidence template-injection issue in spotify-vibe-check.yml. No pull_request_target or workflow_run trigger was observed, so this is a workflow hygiene concern rather than a standalone critical risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jordan Partridge

Direct Dependencies

DependencyLast ReleaseScore
laravel/ai
Version ^0.1
—
—
laravel/mcp
Version ^0.5.9
—
—
illuminate/http
Version ^12.17
—
—
laravel/prompts
Version ^0.3
—
—
php-tui/php-tui
Version ^0.2.1
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform