Package Health

baraveli/rss-scraper

Usable with caveats: the package is documented, tested, licensed, and not deprecated, but it has had no release or repository activity for nearly six years. Depend on it only if its older Laravel support and unchanging behavior fit your project.

Latest v1.3PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitydanger

There were no commits and no active maintainers during the last three months, consistent with the long release pause. This is the main abandonment risk for taking a dependency on the package.

Release historycaution

The latest release was published nearly six years ago, with no releases in the last 12 months. Earlier releases were frequent, but the long pause materially raises maintenance and compatibility concerns.

Repo popularitycaution

The repository has 7 stars and 3 forks, indicating limited external adoption. This is supporting evidence rather than a decisive concern for a small, focused package.

Repo toolingcaution

Composer is used for the build, but no security scanning tooling is present. The missing scanning is a transparency gap, though the repository has no analyzed workflows that add additional risk.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This matters more because the package retrieves remote RSS content, although it is not evidence of maliciousness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

dharis
Mohamed Jinas

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^6.0|^7.0.1

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform