Package Health

zero-to-prod/data-model

Usable with caveats: the repository is active, documented, tested, and not archived, but registry releases have stopped and all recent commits come from one contributor. Review the release gap and maintainer concentration before making it a critical dependency.

Latest v81.20.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dangerous workflowscaution

One of five analyzed workflows contains a script-injection pattern, creating a workflow hygiene concern even though no pull-request-target or untrusted-checkout workflow was detected.

Project backingcaution

The package and repository share the zero-to-prod namespace, but the repository owner is an individual account rather than an organization, so there is no organizational handoff capacity to offset the narrow maintainer base.

Release historycaution

The package has 64 releases over roughly two years, but it has had no registry release in the last 12 months despite the repository receiving a recent push; this is a meaningful maintenance concern.

Repo bus factorcaution

One contributor made all three commits in the last three months, leaving maintenance dependent on a single active person and increasing abandonment risk.

Repo commit activitycaution

The repository recorded three commits in the last three months, showing some ongoing activity, but the volume is modest and does not fully offset the lack of recent registry releases.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

David Smith

Direct Dependencies

DependencyLast ReleaseScore
zero-to-prod/package-helper
Version ^1.1.3
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform