Package Health

atk14/async-file-field

This release appears suitable to depend on: it is stable, not deprecated, has a long release history with four releases in the last 12 months, and the linked organization-owned repository is active and unarchived. The package is licensed under MIT, has a clear README, changelog, and coherent source tree, with no install-time lifecycle scripts and only one runtime dependency. The main concerns are that all seven recent commits came from one contributor, the repository has no security scanning or security policy, and the project has negligible public popularity; these reduce resilience and transparency but do not indicate abandonment given the recent release and commit activity.

Latest v1.0.9PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

A substantial README and changelog are present, and the repository also has a changelog; however, neither the artifact nor repository contains tests, which is a maintenance-quality gap for a functional upload component.

Repo bus factorcaution

All seven recent commits came from a single contributor, creating a clear bus-factor concern; organization ownership partly compensates because maintenance can potentially be handed off internally.

Repo popularitycaution

The repository has zero stars and forks and only two watchers, indicating limited external adoption or review; popularity is supporting evidence rather than a decisive health verdict.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured, leaving a transparency and detection gap.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

ATK14 Development Team

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
18 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform