Package Health

citomni/app-skeleton

This is a generally healthy, actively maintained early-stage package with a stable release, recent repository activity, clear licensing, matching repository identity, organization backing, and a security policy. The main adoption risks are a single-contributor maintenance bottleneck, lack of tests and changelog documentation, and no security-scanning tooling; these are meaningful but not severe enough to make the package unfit to depend on. Its short 95-day history and zero popularity provide limited maturity evidence, so continued maintenance should be monitored.

Latest v1.0.0.3PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo bus factorcaution

One contributor made all eight commits in the last three months, creating a clear maintenance bottleneck. Organization backing partly mitigates handoff risk, but no second active contributor is shown.

Repo popularitycaution

The repository has zero stars, forks, and watchers, providing little external validation or community support. Popularity is supporting evidence rather than a verdict, so this is a modest concern for a young package.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tooling is present. The missing scanner lowers supply-chain assurance without indicating abandonment by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
citomni/kernel
Version ^1.0
—
—
citomni/installer
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform