Package Health

bytic/event-discovery

Its MIT licensing, matching repository, and organization backing improve transparency. The small codebase has no repository tests or security scanning, so pinning this release merits extra care.

Latest 0.9.1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

70

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package scaffoldingcaution

The artifact includes a README, but it is only 17 characters long, and the repository reports no tests or changelog. The compact package may reduce testing needs, but consumer documentation and verification are limited.

Release historycaution

Only two releases have been published, with no release in roughly 2 years and 8 months and a median interval of about 15 months. This indicates sparse maintenance, though the package is not deprecated.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last 3 months, while its last push was in January 2024. That suggests maintenance has stopped for an extended period.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This matters somewhat for dependency maintenance but is partly offset by the package's small scope.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Gabriel Solomon

Direct Dependencies

DependencyLast ReleaseScore
psr/event-dispatcher
Version ^1.0 || ^2.0
—
—
fig/event-dispatcher-util
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform