Package Health

umityatarkalkmaz/upload

This release has strong baseline packaging and transparency: it is MIT-licensed, includes a README, changelog, tests, a complete small source tree, read-only CI permissions, no install-time scripts, and no dangerous workflow patterns. However, it is brand new, with only two releases on the same day, no commit activity beyond the initial publication window, one registry maintainer, minimal repository adoption, no security policy, and no security-scanning tooling. The repository is active and clearly references the package, so these concerns indicate limited maturity and operational depth rather than abandonment; dependency adoption is reasonable with appropriate review and monitoring.

Latest v2.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access. That is a thin publishing base and creates continuity risk, although the linked repository is owned by the same individual and the package is still actively being published.

Project backingcaution

The source repository is owned by an individual rather than an organization. This is not inherently unhealthy, but it means there is no organizational backing signal to offset the single-maintainer continuity risk.

Release historycaution

The package is extremely new: it has only two releases and was first published earlier the same day, so there is little evidence of sustained maintenance or release reliability.

Repo commit activitycaution

There were zero commits and zero active maintainers in the preceding three months. Because the package was only created earlier the same day, this is primarily a coverage and maturity limitation rather than evidence of abandonment, but sustained activity remains unproven.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a newly published project, but it also means there is no demonstrated community maintenance process yet.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Umit Yatarkalkmaz

Direct Dependencies

DependencyLast ReleaseScore
umityatarkalkmaz/string-helper
Version ^2.0

Weekly Downloads

Info

Last Published
21 days ago
Created
21 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform