Package Health

cnvs/canvas

The repository has strong recent commit volume, tests, a security policy, and a clear MIT license. Maintenance depends on one contributor, and all 25 workflow actions are unpinned.

Latest v5.4.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and lists the same package as its replacement, which is a significant adoption risk despite the active repository.

Release historycaution

The registry shows no releases in the last 12 months and the latest release was in August 2020; active repository commits partly compensate, but registry delivery appears stale.

Repo bus factorcaution

One contributor made all recent commits, creating a meaningful continuity risk; the repository's strong activity reduces abandonment concern but does not remove single-maintainer dependence.

Workflow auditcaution

All workflows were analyzed with no dangerous findings, and permissions are read-only, but all 25 action references are unpinned, leaving avoidable build-integrity exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Todd Austin

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ^2.10
—
—
laravel/framework
Version ^6.0|^7.0
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform