Package Health

barth/dev-pack

Its MIT license, clear README, matching repository, and stable version make the package easy to understand. The tiny user base and absent security policy add modest maintenance and transparency concerns.

Latest v1.0.3PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The latest release was published over seven years ago, with no releases in the past 12 months. The four-release history shows a real abandonment concern despite the stable version.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the past three months, and its last push was over five years ago. This strongly limits evidence of ongoing maintenance.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 1 watcher, providing little evidence of a broad community that could compensate for the stale maintenance record.

Security policycaution

No repository security policy was found. This is a transparency gap, though it is less serious because the package is a development-tool pack rather than a security-sensitive runtime library.

Workflow auditcaution

The single workflow was fully analyzed with no audit findings or untrusted sinks, but both action references are unpinned. The missing top-level permissions block is acceptable on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jibé Barth

Direct Dependencies

DependencyLast ReleaseScore
phpmd/phpmd
Version ^2.6
—
—
phpro/grumphp
Version ^0.14.2
—
—
seld/jsonlint
Version ^1.7
—
—
j13k/yaml-lint
Version ^1.1
—
—
sclable/xml-lint
Version ^0.2.4
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform