Package Health

bugover/ratchet

Documentation, tests, licensing, and a matching source repository provide a solid foundation. Maintenance has stalled, with no recent commits or releases, and all three workflow actions are unpinned.

Latest 1.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, a strong sign that maintenance has currently stalled.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the small registry maintainer list offers limited evidence of broader project backing.

Release historycaution

Only two releases exist, with no release in the last 12 months and the latest release more than a year ago, which weakens evidence of ongoing maintenance.

Repo issue activitycaution

There were no new or merged issues or pull requests in the last month, consistent with low current project activity, but this is weaker evidence than the absent commits and releases.

Repo popularitycaution

The repository has zero stars and forks and one watcher, so there is little community corroboration; popularity is supporting evidence and does not outweigh the concrete maintenance signals.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Chris Boden
Matt Bonneau

Direct Dependencies

DependencyLast ReleaseScore
react/socket
Version ^1.0
—
—
guzzlehttp/psr7
Version ^1.7|^2.0
—
—
ratchet/rfc6455
Version ^0.4
—
—
symfony/routing
Version ^6.4|^7.0
—
—
react/event-loop
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform