Package Health

chrisabner/cordon-modulith

The repository is well documented, licensed, tested, and directly tied to the package. All 11 workflow actions are unpinned, and the project has no security-scanning tool, leaving avoidable maintenance and build-integrity gaps.

Latest v0.1.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package is brand new, with only two releases published within the same day, so there is little evidence of sustained maintenance or release stability.

Repo commit activitycaution

The repository shows zero commits and zero active maintainers over the past three months. Because the project was released only recently, this is concerning but not conclusive evidence of abandonment.

Repo popularitycaution

The repository has one star, no forks, and no watchers. This provides little external adoption evidence, though low popularity is less concerning for a package released only hours ago.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. That leaves a transparency and maintenance gap for a package intended to run in application projects.

Version stabilitycaution

Version v0.1.1 is a 0.x release, indicating an alpha-stage API that may change before a mature release, even though it is not marked as a prerelease.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
nikic/php-parser
Version ^5.0
—
—
illuminate/console
Version ^12.0|^13.0
—
—
illuminate/support
Version ^12.0|^13.0
—
—
illuminate/contracts
Version ^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
13 hours ago
Created
14 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform