Package Health

ttpryg/config

Usable with caveats: this is a very new library with only one release and no commits recorded in the last three months, so its maintenance track record is unproven. The linked organization repository has tests, automated dependency updates, a matching README, and no risky workflow patterns, which provides some support for adoption.

Latest 1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

The published artifact has no README, which is a consumer-facing documentation gap for a configuration library, but the source repository does contain a README and tests.

Release historycaution

The package is only 2 days old and has a single release, so there is not enough release history to demonstrate sustained maintenance or compatibility stability.

Repo commit activitycaution

No commits and no active maintainers were recorded in the last three months. Because the repository is only 2 days old, this is more an unproven maintenance record than evidence of abandonment, but it remains a meaningful caveat.

Security policycaution

The repository has no security policy, leaving disclosure and response expectations undocumented for a library that may handle application configuration.

Token permissionscaution

The single workflow does not declare top-level token permissions. Although it declares no top-level write access, explicit least-privilege permissions would provide stronger CI hardening.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Toto

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 days ago
Created
5 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform