Package Health

yormy/xid

Clear licensing, tests, and a matching repository support straightforward maintenance. Releases and commits have stopped, while workflows use unpinned actions and install scripts run.

Latest 1.1.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

The package declares post-autoload-dump, post-install-cmd, and post-update-cmd scripts, so installation and updates execute package-defined commands. This adds operational review cost even without evidence of malicious behavior.

Release historycaution

The package has had no release in roughly two years: its latest release was October 17, 2024, despite seven releases overall. That materially raises abandonment risk, although the package is not deprecated.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the prolonged release gap. This weakens evidence of ongoing maintenance.

Security policycaution

The linked repository has no security policy. That leaves vulnerability-reporting and response expectations unclear, though the repository otherwise provides tests and documentation.

Workflow auditcaution

All 20 analyzed action references are unpinned, and one workflow grants top-level write permissions; no untrusted checkout or script-injection path was found. The audit was complete, but the workflow hygiene is still a maintenance and supply-chain caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Yormy

Direct Dependencies

DependencyLast ReleaseScore
linkorb/xuid
Version ^1.4.0

Weekly Downloads

Info

Last Published
1 year ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform