Package Health

tualo/sass

This is a usable but relatively young package with a stable MIT release, active registry publishing, a substantive source tree, and clear organization-backed repository ownership. However, the repository shows no commits or active maintainers in the last 3 months, has no tests, changelog, security policy, or security scanning, and has no adoption indicators; the bursty release history partly offsets but does not eliminate the maintenance and transparency concerns. It is reasonable for projects that accept a small, organization-maintained dependency, but it warrants continued monitoring before becoming a critical dependency.

Latest 1.0.16PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a modest continuity risk. This is partly compensated by the repository being owned by an organization rather than an individual account.

Package scaffoldingcaution

A README is present, but neither the package nor repository contains tests or a changelog. For a library providing compilation, routes, CLI commands, and integration behavior, the absence of both tests and release documentation is a genuine maintenance and transparency gap.

Repo commit activitycaution

The repository records zero commits and zero active maintainers in the last 3 months, which is the clearest maintenance concern. Recent registry releases and a recent repository push compensate partly, but do not demonstrate sustained source-level activity.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This may reflect a small, low-traffic project, but it provides little evidence of an active user or maintainer feedback loop.

Repo popularitycaution

The repository has zero stars, forks, and watchers, providing no independent adoption evidence. Popularity is supporting evidence rather than a verdict, so this is a modest caution for a young package rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Thomas Hoffmann

Direct Dependencies

DependencyLast ReleaseScore
matthiasmullie/minify
Version 1.3.75

Weekly Downloads

Info

Last Published
18 days ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform