Package Health

caipiao/forcast

Its tiny source tree and missing security policy provide little evidence of ongoing maintenance or review. The package is licensed under MIT, but the repository has not changed in over six years and does not clearly identify this package.

Latest 1.0.2PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

Only two releases were published, both in May 2020, with no releases in roughly six years. That strongly suggests the package is abandoned or frozen.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last three months, consistent with its last push being over six years ago. No newer activity compensates for the long maintenance gap.

Package file treecaution

The package and repository each contain only five files, including no README, tests, or changelog. Such a minimal tree gives consumers little transparency into usage or maintenance, although the license and Composer manifest are present.

Package scaffoldingcaution

The artifact has no README, while tests and a changelog are not expected in published packages; the missing README is a real documentation gap for a library consumers must integrate. No release notes or repository documentation compensate for it.

Repo package mentioncaution

The linked repository name does not match the package name, and no README mention was collected. This raises concern that the repository may not actually be the package's source, though a subpackage or monorepo could explain the mismatch.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

fangyingzhong

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform