Package Health

bolt/bolt-assets

The release is a prerelease from about seven years ago, and all recent repository commits come from one contributor. The MIT license, active organization-owned repository, and lack of install scripts are positive, but the package is intended only as backend assets.

Latest 4.0.0-beta.2.3PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

56

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and identifies bolt/assets as the replacement. This is a direct reason not to start depending on this package.

Release historydanger

The package has had no release in about seven years, despite six releases concentrated in its first month. That makes this specific release stale and raises abandonment risk.

Repo bus factorcaution

One contributor made all five commits in the last three months. Organization ownership provides some handoff capacity, but the observed activity remains concentrated.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention bolt/bolt-assets. Although name differences are normal for subpackages, the combination leaves package ownership less transparent.

Repo toolingcaution

The repository uses Composer for builds but reports no security-scanning tools. That leaves security hygiene less visible, while the small asset-focused scope limits the impact.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Bob den Otter

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform