Package Health

buba71/yamlconfigloader

The package has a small dependency set, a README, tests, and no install-time scripts. Its only release was over five years ago, so future fixes and compatibility updates are uncertain. The linked project has no security policy or scanning tools.

Latest v1.0.0PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

This is the package's only release, published over five years ago, with no releases in the last 12 months. That leaves maintenance and compatibility prospects uncertain.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the thin maintenance history.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, providing little evidence of community review or support. Popularity is supporting evidence, so this is a moderate concern rather than a standalone failure.

Repo toolingcaution

Composer and Make are used for project tooling, but no security scanning tools are configured. This is a hygiene gap for a package whose source is otherwise small and testable.

Repository archivedcaution

The repository is not archived, which preserves the possibility of future maintenance, but its last push was over five years ago and reinforces the stale release history.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

De Lima David

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^5.3@beta

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform