Package Health

yarri/email-parser

It includes tests, a changelog, a clear README, and a license. No security policy is published, and the workflow's action references are not pinned.

Latest v0.2.4PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

One contributor made all four recent commits, giving the project a top-contributor share of 100%. With user-owned project backing, this leaves maintenance dependent on a single person.

Repo commit activitycaution

The repository had four commits in the last three months, showing recent activity, but all were produced by one active maintainer. The activity is positive but narrow.

Security policycaution

No security policy is present. For an email-parsing library, the missing disclosure and response guidance is a real transparency gap, though it is not evidence of a security defect.

Version stabilitycaution

Version v0.2.4 is not a prerelease, but the package remains below 1.0, so API maturity and compatibility are less established than for a stable-major release.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, leaving dependency versions able to change unexpectedly.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jaromir Tomek

Direct Dependencies

DependencyLast ReleaseScore
pear/pear
Version ^1.10
atk14/files
Version ^1.6
atk14/translate
Version ^1.2
yarri/utf8-cleaner
Version ^1.1
atk14/string-buffer
Version ^1.2

Weekly Downloads

Info

Last Published
2 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform