Package Health

bagart/telegram-bot-lib

This is a usable but very young pre-1.0 package with strong basic transparency: it has an MIT license and license file, a substantial 875-file artifact, README and tests, no install-time lifecycle scripts, a matching repository, and 10 commits in the last three months. However, it has only two releases over 9 days, remains at v0.1.1, all recent commits come from one contributor, and the repository has no security scanning or security policy. The repository is not archived or deprecated, so this is not an abandonment verdict, but its short history and single-maintainer concentration warrant caution before adopting it for a critical dependency.

Latest v0.1.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Project backingcaution

The repository is owned by a user account rather than an organization, so the single-contributor concentration is not compensated by visible organizational backing.

Release historycaution

Only two releases exist and the package is just 9 days old, so there is insufficient release history to establish long-term maintenance reliability.

Repo bus factorcaution

All 10 recent commits were made by one contributor, creating a genuine continuity and handoff risk for a user-owned project without organizational backing.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Given the package's age, this is supporting evidence of limited adoption rather than a decisive health failure.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected; the missing security automation is a hygiene gap for a dependency intended to handle bot integrations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

BAGArt (Artur Baltaev)

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^2.0
—
—
bagart/ask-client
Version *
—
—
bagart/async-kernel
Version *
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform