Package Health

chrisharrison/event-sourcing

The stable 1.0.0 release and lack of install-time scripts are modest positives. No release has appeared since April 2020, and the linked repository contains only composer.json with no tests or changelog, leaving little evidence of ongoing maintenance.

Latest 1.0.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package file treedanger

Both the published artifact and linked repository contain only composer.json. That unusually minimal tree provides little transparency into implementation, testing, or maintenance.

Release historydanger

The package has made only one release, on April 17, 2020, with no releases in roughly six years. This is strong evidence of abandonment risk despite the package not being deprecated.

Package scaffoldingcaution

The artifact having no tests, changelog, or README is not inherently concerning for a published PHP artifact, but the repository also reports no tests or changelog, so there is no visible project documentation or validation evidence to compensate for the long inactivity.

Repo popularitycaution

The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counters provide no additional maturity signal for this otherwise inactive project.

Repo toolingcaution

Composer is used as the build tool, showing basic ecosystem-standard packaging, but no security scanning tools are configured. This is a minor transparency gap rather than a standalone severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Chris Harrison

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform