Package Health

chebur/rabbitmq-consumer-decorator-newrelic

Usable with caveats: the package is licensed, not deprecated or archived, and its repository matches the package. However, it has had no release or commit activity for over four years, has no tests, and has very little adoption evidence, so verify compatibility before depending on it.

Latest 0.2.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitydanger

There have been zero commits and zero active maintainers in the last three months, consistent with the long gap since the last release and increasing abandonment risk.

Release historycaution

The package has only three releases and none in the last four years, with the latest release on January 16, 2022. That is a meaningful maintenance concern for a dependency.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, providing little supporting evidence of broad community use or review.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are configured. This is a transparency and maintenance gap, though the absence of scanning is not by itself evidence of an unsafe package.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for consumers.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Vladimir Chebotarev

Direct Dependencies

DependencyLast ReleaseScore
ekino/newrelic-bundle
Version ^2.2
—
—
php-amqplib/rabbitmq-bundle
Version ^1.14|^2.2
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform