Package Health

bhuvidya/craft-cachebust

Risky to adopt: the package has had no release or repository activity for about six years, and its README is still skeletal. It is not deprecated or archived and has a straightforward Composer dependency, but the long abandonment gap makes it a maintenance liability.

Latest 1.0.2PackagistPackagist

44%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published about six years ago, with no releases in the last 12 months and only two releases overall. That long period without updates is strong evidence of abandonment risk for a dependency.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release hiatus. No provided activity signal shows ongoing maintenance capacity.

Package scaffoldingcaution

The package includes a README and changelog, but the 806-character README contains unfinished sections such as “-Insert text here-” and no tests are present; missing tests are normal packaging practice, but the incomplete consumer documentation is a real transparency gap.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools are configured. This is a modest transparency gap rather than a severe risk, especially since the repository has no workflows to expose additional automation concerns.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This weakens project transparency but is less significant than the clear lack of maintenance activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

bhu Boue vidya

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^3.0.0-RC1

Weekly Downloads

Info

Last Published
6 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform