Package Health

alloy/alloy_compact_menu

The module is extremely small and lacks a README, tests, changelog, and repository security policy. Its organization-owned repository remains active enough to avoid abandonment concerns, but the package has only two releases and none in the last 12 months.

Latest 1.0.1PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package scaffoldingcaution

The artifact has no README, tests, or changelog, and the repository also reports none. The missing README modestly reduces consumer transparency for a Drupal module, while missing tests and changelog are otherwise normal packaging gaps.

Release historycaution

Only two releases exist, with the latest published on November 27, 2024 and none in the last 12 months. This indicates a thin and currently inactive release history, though it does not by itself prove abandonment.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull request activity in the last month. Combined with the sparse release history, this provides little evidence of an active maintenance community.

Repo popularitycaution

The repository has zero stars and forks and only two watchers. This is weak supporting evidence, but popularity is not decisive for a small module.

Repo toolingcaution

Composer is used as a build tool, which is appropriate for this package, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform