Package Health

bear/tool-use

bear/tool-use 0.5.0 appears usable and reasonably well-maintained, with five releases over the last 163 days, a latest release published recently, an active non-archived repository, substantial documentation, tests, a changelog, CI and static-analysis workflows, and organization ownership. The main concerns are that it remains a pre-1.0 package, all five commits in the last three months came from one contributor, there is no repository security policy or security-scanning tooling, and the workflows do not declare top-level token permissions. These issues warrant review before adoption but do not outweigh the evidence of active development and solid project scaffolding.

Latest 0.5.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access. This is not decisive because the repository is organization-owned, but it still provides limited evidence about registry publishing redundancy.

Repo bus factorcaution

One contributor made all five commits in the last three months, creating a concentrated maintenance risk; organization ownership provides some ability to hand off maintenance but does not remove the current concentration.

Repo issue activitycaution

There are eight open issues and two new issues in the last month, while two pull requests were merged; the absence of recently closed issues suggests some backlog, but demonstrated merges provide compensating maintenance evidence.

Repo toolingcaution

Composer build tooling and CI-related quality configuration are present, but no security-scanning tool was detected, leaving a security-hygiene gap.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Yoshitaka Jingu

Direct Dependencies

DependencyLast ReleaseScore
ray/di
Version ^2.18
bear/resource
Version ^1.10
phpdocumentor/reflection-docblock
Version ^5.2 || ^6.0

Weekly Downloads

Info

Last Published
11 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform