Package Health

carnage/cqorms

The small codebase has limited project hygiene and no security policy. Its MIT license and matching repository are positives, but the package remains a substantial abandonment risk for new dependencies.

Latest 0.3.1PackagistPackagist

31%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The latest release was in December 2017, with no releases in the last 12 months. This long period without published maintenance is a strong abandonment concern.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's prolonged release inactivity.

Package file treecaution

The package contains a small, focused 12-file implementation and its repository tree matches the artifact, which supports transparency but provides little evidence of mature project infrastructure.

Package scaffoldingcaution

A README is present, and the absence of tests or a changelog in the published artifact is normal packaging practice. The README is very short, so it offers limited consumer guidance.

Project backingcaution

The repository is owned by a user account rather than an organization, so there is no shown organizational backing to compensate for the thin maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
carnage/cqrs
Version ^0.2.0
jms/serializer
Version ^1.1.0
doctrine/doctrine-orm-module
Version ^1.0.0
zendframework/zend-servicemanager
Version ^2.5 || ^3.0

Weekly Downloads

Info

Last Published
8 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform