Package Health

arefshojaei/kitdash

KitDash 2.1.0 appears generally suitable to depend on: it is a stable, non-deprecated package with recent release activity, a repository that is not archived, 44 commits in the last 3 months, comprehensive README and test coverage, and a small runtime dependency profile. The main concerns are that all recent repository activity comes from one contributor, the repository has no security scanning or security policy, and the project has minimal external adoption evidence and no changelog. These are meaningful transparency and continuity risks, but they are outweighed by the package's recent maintenance, explicit licensing, tests, and coherent repository structure.

Latest 2.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health checks

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational maintenance backing to compensate for contributor concentration.

Repo bus factorcaution

Only one contributor made all 44 commits in the last 3 months, creating a clear continuity and abandonment risk if that maintainer becomes unavailable.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is neutral to mildly limiting evidence because it may reflect a small or unused project rather than successful issue resolution.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 1 watcher. This is weak adoption evidence, though popularity is supporting evidence rather than a health verdict and does not outweigh the observed maintenance activity.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tool is configured. Build tooling supports reproducibility, while the missing security automation leaves a hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

ArefShojaei

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform