Package Health

yevhenlisovenko/nano-service

This release appears generally healthy and usable: it is MIT-licensed, stable, non-deprecated, backed by a non-archived repository, and has strong artifact documentation, tests, and changelog coverage. The package has released 36 times in the last 12 months and published v8.5.0 recently, but the repository records no commits or active maintainers in the last three months, creating a maintenance-consistency concern despite the recent release. Low repository adoption, absent security scanning and security policy, and a single registry maintainer further limit transparency, though these concerns do not outweigh the package’s substantial documentation, testing, and release history.

Latest v8.5.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

Nine runtime dependencies, including RabbitMQ, logging, UUID, and cryptographic components, create meaningful transitive maintenance exposure, but the profile is consistent with the package’s event-driven microservice functionality.

Maintainerscaution

Only one registry account, Awescode GmbH, has publish access. This limits publishing redundancy, although registry access records do not establish who actively maintains the code.

Project backingcaution

The repository is owned by an individual GitHub user rather than an organization, so the project has limited visible institutional backing. This is a modest continuity concern, not a conclusion about maintenance quality.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months, which conflicts with the recent registry release and suggests that ongoing maintenance activity may be thin or release-driven.

Repo popularitycaution

The repository has only 4 stars, 0 forks, and 1 watcher, indicating limited external adoption and review. Popularity is supporting evidence rather than a decisive health measure, so this is a modest concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Awescode GmbH

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
—
—
ramsey/uuid
Version ^3 || ^4
—
—
league/statsd
Version ^2.0
—
—
spatie/crypto
Version ^2.0
—
—
monolog/monolog
Version ^2.0 || ^3.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform