Package Health

arout/rhapsody-core

The MIT license, release notes, and Composer/Sonar tooling improve transparency. The project is about three months old and all 91 recent commits come from one maintainer, while no security policy is published.

Latest v2.2.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The repository is owned by a user account rather than an organization, so the concentrated maintainer activity is not offset by visible organizational backing.

Repo bus factorcaution

One contributor made 100% of the 91 commits in the last three months, leaving no demonstrated second maintainer to provide continuity.

Repo commit activitycaution

The repository recorded 91 commits in the last three months, indicating active development. However, the activity is concentrated in one maintainer, which limits independent continuity evidence.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but the recent release and commit activity provide stronger evidence of current maintenance.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a framework with many runtime dependencies.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.21
filp/whoops
Version ^2.18
doctrine/orm
Version ^2.17
doctrine/dbal
Version ^3.7
predis/predis
Version ^2.2

Weekly Downloads

Info

Last Published
3 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform