Package Health

tourze/wechat-mini-program-user-contracts

The package is MIT-licensed, tested, and clearly tied to its source repository. Its small audience and absent security policy add modest uncertainty; pin this exact version when adopting it.

Latest 1.0.0PackagistPackagist

73%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package is 501 days old with four releases, but only one release in the last 12 months, indicating limited recent maintenance activity.

Repo popularitycaution

The repository has zero stars and forks and one watcher, so there is little external adoption evidence; this is only a modest concern because popularity is supporting evidence rather than a health verdict.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear for users and maintainers.

Workflow auditcaution

All three analyzed action references are unpinned, weakening build reproducibility, although both workflows were analyzed cleanly and no dangerous triggers or high-confidence findings were reported.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tourze/wechat-mini-program-appid-contracts
Version 1.0.*
—
—

Weekly Downloads

Info

Last Published
11 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform