Package Health

tzfrs/googlesitemapparser

The package has a clear README, matching repository, stable version, and simple two-dependency install path. Its single maintainer, absent tests and security policy, and modest adoption leave limited evidence of ongoing care.

Latest 1.0.9PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

One registry maintainer is a thin publishing base for a user-owned project, increasing continuity risk if that person stops maintaining it.

Release historycaution

The last release was over 9 years ago, with no releases in the past 12 months. This is a meaningful maintenance concern, though the package is not deprecated and has a stable release history.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the past 3 months, consistent with the long release gap. The repository remains available, but current maintenance capacity is unclear.

Repo popularitycaution

The repository has 14 stars and 5 forks, indicating modest adoption. Popularity is only supporting evidence, so this slightly limits confidence rather than determining the verdict.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a package that parses remote sitemap content.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Theo Tzaferis

Direct Dependencies

DependencyLast ReleaseScore
jyggen/curl
Version v3.0.1

Weekly Downloads

Info

Last Published
10 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform