Package Health

citadel/aureum

This is an actively maintained, non-deprecated stable release with a substantial recent release history, current repository activity, tests, build tooling, and a repository that clearly matches the package. The main concerns are that all 83 commits in the last three months came from one maintainer, the project has no security policy or security-scanning tooling, and releases occur at an unusually high frequency with a median interval of about 1 hour, which may indicate rapid iteration and warrants version pinning and review. The zero-star repository provides little independent adoption evidence, but is not decisive for a small package.

Latest 1.12.2PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Project backingcaution

The repository is owned by the user account mous13 rather than an organization, so the single-maintainer concentration is not visibly offset by organizational backing.

Repo bus factorcaution

One contributor made all 83 commits in the last three months, creating a concentrated bus factor and making continuity dependent on a single individual.

Repo popularitycaution

The repository has zero stars, forks, and watchers, so there is little evidence of external adoption or review; this is supporting caution rather than a standalone abandonment verdict.

Repo toolingcaution

The repository uses Make and Composer build tooling, but has no security-scanning tools; the build support is positive while the missing security automation is a genuine hygiene gap.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and maintainer response guidance undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
dompdf/dompdf
Version ^3.1
—
—
forumify/forumify-platform
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
29 days ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform