Package Health

beapi/composer-scaffold-plugin

The organization-backed repository is still active and the package includes a README, changelog, and no install-time scripts. Its single recent contributor and conflicting license records warrant checking ownership and licensing before adoption.

Latest 2.4.4PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The manifest declares MIT, but the artifact license file is detected as GPL-3.0 and the README also describes GPLv3-or-later licensing. The release is licensed, but the mismatch needs resolution before use.

Release historycaution

The latest release was over two years ago, with no releases in the last 12 months, which lowers confidence in release maintenance. The long history of 13 releases provides some maturity evidence.

Repo commit activitycaution

The repository recorded one commit in the last three months, showing some current activity, although the pace is too thin to offset the absence of releases over the last 12 months.

Repo toolingcaution

The project uses Composer for builds, which fits the package ecosystem. No security scanning tools were detected, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy, reducing clarity about how vulnerabilities should be reported and handled. This is a hygiene concern rather than evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

BeAPI

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ^1.9 || ^2.0

Weekly Downloads

Info

Last Published
2 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform