Package Health

thedagofugo/blade-dago-icons

It has a clear MIT license, matching source repository, repository tests, and a documented release. Maintenance has been inactive since September 2024, while all nine workflow actions are unpinned and no security policy or scanning is present.

Latest 1.0.6PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has had no releases in the last 12 months, and its latest recorded release was in September 2024 despite being 761 days old. This indicates meaningful maintenance risk, although four total releases show the project was previously published actively.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no recent activity to offset the inactivity.

Security policycaution

No security policy was found in the linked repository, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is partly offset by the repository's otherwise complete project structure.

Workflow auditcaution

All 9 analyzed action references are unpinned, creating avoidable build reproducibility and action-update risk. The audit found no untrusted checkout, script injection, or high-severity issue, and two workflows use job-level permissions, so this is a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

TheDagofugo

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^8.0|^9.0|^10.0|^11.0
—
—
blade-ui-kit/blade-icons
Version ^1.1
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform