Package Health

boshurik/mapper

The package is lightweight, with one runtime dependency, a README, and a tested source tree. Its last release was over five years ago, and repository activity has stopped. A single maintainer and no security scanning reduce confidence in ongoing support.

Latest 0.2.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historydanger

The latest release was over five years ago, with no releases in the last 12 months and only four releases overall. This is meaningful abandonment risk for a library, despite the package not being deprecated.

Maintainerscaution

The registry lists one maintainer, and the repository owner is an individual rather than an organization. That is workable for a small package but leaves limited demonstrated maintenance capacity.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The project is not archived, but there is no recent maintenance evidence.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tool is present. For this small library that is a hygiene gap rather than a standalone adoption blocker.

Version stabilitycaution

Version 0.2.2 is not marked as a prerelease, but the package remains below a stable major version. This is a minor maturity concern, partly offset by the clearly usable README and tests.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

BoShurik

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform