Package Health

arnaudleroy-studio/coffeetrove

The repository is minimal, with no security scanning or security policy. It is not deprecated, has a clear MIT license, and provides a usable README.

Latest v0.1.1PackagistPackagist

63%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Package file treecaution

The artifact and repository each contain only four files, providing limited visible project structure for a PHP client of this scope.

Release historycaution

The package is 174 days old and has only two releases, both published on the same day, so there is little evidence of sustained release maintenance.

Repo toolingcaution

Composer is used for builds, but no security-scanning tools are present, leaving a maintenance and assurance gap.

Security policycaution

The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.

Version stabilitycaution

Version v0.1.1 is not a stable-major release, which is consistent with a young package but indicates a less mature compatibility commitment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Arnaud Leroy

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 months ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform