Package Health

azhida/laravel-work_wechat_message

The package has a clear README, a matching source repository, a small dependency surface, and release notes for this version. Missing security scanning and a security policy reduce transparency for a package handling message data.

Latest 0.1.2PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has had no release in nearly five years: six releases were published overall, but none appeared in the last 12 months. This is strong evidence of abandonment risk despite the short early release intervals.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving maintenance capacity unproven.

Repo popularitycaution

The repository has only 2 stars, 1 fork, and 1 watcher. Low popularity is supporting evidence rather than decisive on its own, but it provides little compensating community signal for the dormant project.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. The missing scanning reduces supply-chain maintenance transparency, although it does not by itself show a defect in the release.

Security policycaution

The repository has no security policy, which weakens the process for reporting and handling issues in a package that processes workplace messages. This is a transparency gap, but not severe on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

azhida

Direct Dependencies

DependencyLast ReleaseScore
azhida/tools
Version ^0.3.1
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform