Package Health

withinboredom/common-records

The project includes tests, clear documentation, a matching source repository, and a recent release note. Its single maintainer, stalled release and commit activity, and unpinned workflow actions add ongoing maintenance and build-integrity concerns.

Latest v0.2.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Maintainerscaution

One registry maintainer is responsible for publishing the package. The matching user-owned repository supports clear ownership, but the narrow maintainer base increases continuity risk.

Release historycaution

The package has had three releases, but none in the last 12 months and its latest release was about 15 months ago. This is a meaningful maintenance concern, though the repository was pushed more recently.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance. The recent repository push provides limited compensation but does not show sustained activity.

Security policycaution

The linked repository has no security policy. This is a transparency gap, although the package has no reported workflow audit findings and uses Dependabot for scanning.

Workflow auditcaution

The workflow is fully analyzed, uses read-only permissions, and has no reported audit findings, but all three action references are unpinned. That leaves avoidable build-integrity exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Robert Landers

Direct Dependencies

DependencyLast ReleaseScore
withinboredom/records
Version ^0.1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform