Package Health

chubbyphp/chubbyphp-framework-router-fastroute

This is a generally healthy, established package: it has been maintained since 2020, released 6 times in the last 12 months, is on a stable major version, is not deprecated, and has a matching active source repository with repository tests, Composer tooling, security scanning, and no identified dangerous workflow patterns. The main concerns are concentrated maintenance, with one contributor responsible for all recent commits, very low repository popularity, no repository security policy, and unspecified GitHub Actions token permissions. The artifact is minimal and omits tests and a changelog, but the linked repository contains both, which compensates for those packaging gaps. It appears reasonable to depend on, with normal caution about maintainer concentration and repository security hygiene.

Latest 2.3.5PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All recent commits come from one contributor, creating a concentrated maintenance dependency. The organization-owned repository partially mitigates the risk because maintenance can potentially be transferred within the project.

Repo commit activitycaution

There was 1 commit in the last 3 months from 1 active maintainer. Recent activity exists, but the low volume limits evidence of sustained maintenance capacity.

Repo popularitycaution

The repository has only 1 star, 1 fork, and 1 watcher. Low popularity is supporting caution about external adoption and community depth, but it does not outweigh the package's release and maintenance evidence.

Security policycaution

No security policy is present in the repository, leaving vulnerability-reporting expectations and response procedures undocumented.

Token permissionscaution

The one workflow lacks top-level token permissions declarations. No write permissions were observed, but explicitly constraining the token would provide stronger CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dominik Zogg

Direct Dependencies

DependencyLast ReleaseScore
nikic/fast-route
Version ^1.3.1|2.0.0-beta1|^2.0
—
—
psr/http-message
Version ^1.1|^2.0
—
—
chubbyphp/chubbyphp-framework
Version ^6.1.2
—
—
chubbyphp/chubbyphp-http-exception
Version ^1.3.4
—
—

Weekly Downloads

Info

Last Published
29 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform