Package Health

aldean55670/drive

This release is usable in principle, but it is an extremely immature dependency: the package is newly published, has only two releases, no observed recent commit activity, no tests, no README or changelog, no security policy, and no security scanning. The repository is not archived, the package is not deprecated, it has a matching repository, uses Composer, includes a license file, and has no install-time scripts or dangerous workflows, which reduce immediate adoption risk. Overall, the limited history and sparse maintenance and transparency evidence warrant caution before taking a dependency on it.

Latest v3PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package file treecaution

The package contains only 10 files, centered on composer.json, src/index.php, and generated Composer autoload files. This may reflect a minimal package, but it provides little evidence of testing, documentation, or development maturity.

Package scaffoldingcaution

The artifact and repository contain no README, tests, or changelog. For a package with only a small source tree, this is still a meaningful transparency and verification gap because no provided signal compensates for it.

Project backingcaution

The repository is owned by an individual user rather than an organization. Individual ownership is not inherently unhealthy, but combined with the package's zero-day age and absent activity history it provides limited evidence of sustained backing.

Release historycaution

The package is 0 days old with only two releases and one release in the last 12 months, so there is almost no release history from which to establish maintenance reliability or long-term stability.

Repo commit activitycaution

The repository reports zero commits and zero active maintainers over the last three months. Because the package is newly created, this is partly explained by its age, but it leaves maintenance capacity entirely unproven.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
23 days ago
Created
23 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform