Package Health

caiyun/license-client

This is a usable but very young package with several positive health indicators: it is not deprecated or archived, has a stable non-prerelease version, includes a substantive README, tests, a license file, and no install-time lifecycle scripts. Its main risks are limited maturity and continuity: the package is only 30 days old, all 7 recent repository commits came from one contributor, repository popularity is currently zero, and there is no security policy or security-scanning tooling. The recent release and commit activity show active development, but the narrow maintainer base means developers should monitor maintenance closely before taking a long-term dependency.

Latest v2.0.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Project backingcaution

The source repository is owned by a GitHub user account rather than an organization. This does not indicate poor quality, but it provides less evidence of institutional maintenance capacity and does not compensate for the concentrated contributor activity.

Release historycaution

Six releases in the package's first 30 days, with a median interval of about 6 hours, demonstrate active initial development but provide little evidence of long-term maintenance or release stability.

Repo bus factorcaution

One contributor made all 7 commits in the last three months, giving a 100% top-contributor share. Because the repository is user-owned rather than organization-owned, there is no provided project-backing evidence that offsets this concentrated bus factor.

Repo commit activitycaution

Seven commits in the last three months, all during the package's short observed lifetime, show active work. However, activity from only one active maintainer limits evidence of sustained maintenance capacity.

Repo popularitycaution

The repository has zero stars, forks, and watchers, providing no external adoption evidence. Given the package is only 30 days old, this is a maturity and supportability caution rather than proof that the package is unsafe to depend on.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version ^3.0
illuminate/http
Version ^12.0|^13.0
illuminate/console
Version ^12.0|^13.0
illuminate/routing
Version ^12.0|^13.0
illuminate/support
Version ^12.0|^13.0

Weekly Downloads

Info

Last Published
20 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform