Package Health

charlama/framework

The framework has a stable MIT release and no install-time scripts, but its small source tree offers little evidence of ongoing care. Four runtime dependencies, no security tooling or policy, and a repository that does not clearly identify the package add adoption risk.

Latest 1.0.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

There has been only one release, published about 570 days ago, with no releases in the last 12 months. That provides weak evidence of maturity or continuing maintenance.

Repo commit activitydanger

The repository had zero commits and zero active maintainers in the last three months. Combined with the one-release history, this is strong evidence that maintenance has stalled.

Dependency profilecaution

Four runtime dependencies, including the PHP runtime and three framework libraries, create a meaningful dependency surface but are not excessive for a PHP micro framework.

Maintainerscaution

Only one registry maintainer is listed, so publishing continuity depends on a single person and has limited redundancy.

Package scaffoldingcaution

The published artifact has no README, tests, or changelog. Missing tests and changelog are normal for a published artifact, but the absent README reduces documentation for a framework consumers must integrate with.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Saud Karic

Direct Dependencies

DependencyLast ReleaseScore
spatie/ignition
Version ^1.15
—
—
jenssegers/blade
Version dev-master
—
—
rakit/validation
Version dev-master
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform