Package Health

0daysolution/composer-asset-plugin-assagist

Its five-file layout, readable installation guidance, and lack of install-time scripts keep the package simple to integrate. The repository has no security policy or security scanning, leaving maintenance and security practices difficult to verify.

Latest v1.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The latest release was published in May 2016, and there have been no releases in roughly 10 years. Four total releases provide little evidence of ongoing maintenance.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap. The repository is not archived, but there is no observed recent activity to offset the concern.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured. That weakens evidence of routine security maintenance, though it does not by itself indicate a vulnerable release.

Security policycaution

The linked repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a transparency gap for a package that integrates with Composer.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Danil Syromolotov

Direct Dependencies

DependencyLast ReleaseScore
fxp/composer-asset-plugin
Version ^1.1.4
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform