Package Health

triwinvendor/google-pubsub

Licensing, documentation, and packaging are in good shape. The only release is over three years old, with no recent commits or issue activity, and the repository has no security scanning.

Latest 1.0.0PackagistPackagist

35%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historydanger

There has been only one release, on October 13, 2022, with no releases in the last 12 months. That is strong evidence of an unmaintained package.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old last push, this materially increases abandonment risk.

Project backingcaution

The repository is owned by an organization, which can provide backing beyond a short registry maintainer list. However, the provided activity signals show no recent evidence that this backing is active.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month. This supports the broader inactivity concern, although a zero issue count alone is not severe.

Repo package mentioncaution

The repository name matches the package, but its README does not mention this exact package. Because the README instead presents the upstream Google Cloud component, the linkage and publishing ownership are less transparent.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
google/gax
Version ^1.1
google/cloud-core
Version ^1.39

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform