Package Health

catfan/medoo

Healthy and suitable to depend on. It has a long release history, a recent stable release, active commits, tests, clear licensing, and a matching source repository; the main caveat is that all recent commits come from one contributor and the repository lacks a security policy.

Latest v2.6.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Project backingcaution

The registry namespace and repository are owned by the same individual account, so there is no organization backing to offset the concentrated maintainer base. The package's long history and current activity still provide meaningful support.

Repo bus factorcaution

One contributor made all 18 commits during the last three months, creating a genuine continuity risk. The active release cadence and substantial project maturity partly compensate, but they do not remove the single-maintainer dependence.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools were detected. This is a modest transparency and assurance gap rather than evidence that the package is unsafe.

Security policycaution

The repository has no security policy, so vulnerability reporting and disclosure expectations are less explicit. The mature repository and active maintenance provide some compensation, but this remains a documentation gap.

Token permissionscaution

The one workflow has no top-level token permissions declaration. Although it requests no declared top-level write access, explicitly limiting permissions would provide stronger CI security hygiene.

Vulnerabilities

TitleVersionsSeverity
CVE-2019-10762
catfan/medoo is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 1.7.5.
0.0.0 - 1.7.5
Critical

Package versions

Maintainers

Angel Lai

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 month ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform