Package Health

bex/behat-skip-tests

The small codebase is clearly packaged, licensed, documented, and tied to its repository. Install-time scripts, no security policy, and limited project reach add meaningful maintenance and hygiene concerns.

Latest 1.2.0PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The latest release was in May 2018, more than eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, although the package is small and stable.

Lifecycle scriptscaution

post-install-cmd and post-update-cmd scripts run during dependency operations. This adds install-time behavior that should be understood before adoption, even though no maliciousness conclusion follows from it.

Maintainerscaution

Only one registry maintainer is listed. That is workable for a small user-owned package, but it leaves limited visible publishing resilience if the maintainer stops responding.

Project backingcaution

The repository is owned by an individual rather than an organization. That is consistent with a small package, but it offers less visible institutional backing for long-term maintenance.

Repo issue activitycaution

There is one open issue and no issue or pull-request activity in the last month. Combined with the old last push, this supports a conclusion of inactive maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tibor Kotosz

Direct Dependencies

DependencyLast ReleaseScore
behat/behat
Version ^3.0.0

Weekly Downloads

Info

Last Published
8 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform