Package Health

bitinflow/expose

Risky to adopt: the package appears effectively unmaintained, with no releases or repository pushes since July 2022. It has a real MIT license, tests and a changelog in the repository, but the long maintenance gap makes it a liability for new projects.

Latest 2.2.3PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Release historydanger

Only two releases were published, both in July 2022, with no releases in the last 12 months despite the package being over four years old. This is strong evidence of abandonment risk.

Lifecycle scriptscaution

The package defines a post-create-project-cmd lifecycle script. Such a script can run automatically during project setup and deserves review, although this signal alone does not establish a health or safety verdict.

Repo issue activitycaution

There were no new issues, pull requests, or merged pull requests in the last month, and no pull requests were open. This provides no evidence of ongoing maintenance.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption or community-maintenance reassurance.

Repository archivedcaution

The repository is not formally archived, but its last push was on July 7, 2022, matching the stale registry history. The lack of recent repository activity materially offsets the unarchived status.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

René Preuß
Marcel Pociot

Direct Dependencies

DependencyLast ReleaseScore
laravel-zero/phar-updater
Version ^1.2

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform