Package Health

bangsamu/library-clay

This is a usable, actively released Composer package with 50 releases over roughly 3 years, 21 releases in the last 12 months, a stable non-prerelease version, an MIT license, and no registry deprecation or install-time lifecycle scripts. However, the linked user-owned repository shows no commits or active maintainers in the last 3 months, has no tests, changelog, security policy, or security-scanning tooling, and has negligible adoption signals. The coherent 16-file package tree and matching repository provide some transparency, but the thin validation and security processes make this a caution-level dependency rather than a strongly mature one.

Latest v1.0.47PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months. This conflicts with the strong registry release cadence and raises concern that releases may not reflect sustained source-level maintenance.

Maintainerscaution

Only one registry publishing account is listed. The repository is user-owned rather than organization-owned, so there is limited visible publishing redundancy and some bus-factor concern.

Package scaffoldingcaution

A README is present, but it is only 61 characters and both the artifact and repository lack tests and a changelog. For a framework package containing controllers, services, middleware, and routes, the absence of tests is a meaningful maintenance and regression risk.

Project backingcaution

The repository owner is a user account, not an organization, so there is no organizational backing signal to compensate for the single publisher or thin contributor evidence.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently negative, but it provides no evidence of an active feedback or review process.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

infomediaku.com

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
13 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform