Package Health

andesite/core

A single maintainer, no security policy, and no security scanning reduce confidence in long-term support. The repository is not archived and the package declares MIT licensing, but the package-to-repository naming mismatch needs verification.

Latest 1.2.43PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was about four years ago, with no releases in the last 12 months. Despite 106 historical releases, this strongly indicates the package is no longer maintained.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.

Maintainerscaution

Only one registry account has publish access. That is a thin publishing base for a broad framework-like package and increases continuity risk alongside the lack of recent activity.

Package scaffoldingcaution

The package contains no readme, tests, or changelog, reducing transparency for a library consumers must integrate. The absence of tests and changelog in the published artifact is otherwise normal packaging practice.

Repo package mentioncaution

The repository name does not match andesite/core, and the package name was not found in the repository README. That raises uncertainty about whether the linked source is the intended project.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Gergely Laborci

Direct Dependencies

DependencyLast ReleaseScore
rah/danpu
Version ^2.7
twig/twig
Version ^2.0
symfony/yaml
Version ^4.2
redant/console
Version ^1.0
clue/socket-raw
Version ^1.4

Weekly Downloads

Info

Last Published
4 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform