Package Health

changcannon/comparison

The package is small and easy to inspect, with one runtime dependency and no install-time scripts. However, it has had no release or repository activity since May 2019, and its repository has no tests or security policy, leaving limited evidence of ongoing maintenance.

Latest v1.1.1PackagistPackagist

42%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The last of 8 releases was published in May 2019, with no releases in the past seven years. That long period without updates is strong evidence of abandonment risk, even for a small stable package.

Package scaffoldingcaution

The package includes a README and the repository uses GitHub releases, but the README is only 13 characters and neither the package nor repository reports tests or a changelog. Missing tests and the extremely thin documentation reduce transparency for a library consumers must integrate.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no additional indication of an active user or contributor community.

Repository archivedcaution

The repository is not archived, but it was last pushed in May 2019, matching the stale registry history. The unarchived status provides little compensation for the absence of recent activity.

Security policycaution

The repository has no security policy. This is a transparency and maintenance gap, although the package's small five-file structure limits how much evidence can reasonably be expected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

cannon

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform