Package Health

caweb/phpdoc

The package has a small dependency surface and a valid MIT declaration. Its repository is not archived, but the lack of a security policy and scanning leaves little evidence of ongoing care.

Latest 1.0.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

This is the package's only release, published about three years ago, with no releases in the last 12 months. That strongly suggests abandonment rather than an established maintenance cycle.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers over the last three months, consistent with the roughly three-year gap since publication. This is a substantial abandonment concern.

Maintainerscaution

Only one registry account has publish access, and the repository is user-owned rather than organization-backed. A single publisher is not inherently unsafe, but it leaves limited visible continuity if that maintainer stops responding.

Repo popularitycaution

The repository has zero stars, forks, and watchers, offering no supporting evidence of community adoption or review. Popularity is not required for health, but here it does not offset the inactivity.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, especially alongside the inactive repository.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Danny Guzman

Direct Dependencies

DependencyLast ReleaseScore
phpdocumentor/shim
Version ^3.4

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform