Package Health

collei/rovi

Rovi is usable but still an immature dependency. It has a clear MIT license, stable non-prerelease versioning, no registry deprecation, a matching repository, and very strong recent commit activity. However, the package is only 29 days old, all recent commits come from one contributor, there are no tests or changelog, the repository has no security scanning or security policy, and adoption signals are minimal. These concerns do not make the release unfit, but they increase maintenance, transparency, and continuity risk; reassess it as the project matures.

Latest v1.1.4PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access. This is not by itself a severe concern, but it adds continuity risk for an independently owned package and aligns with the repository's single-contributor profile.

Package scaffoldingcaution

A substantive README is present, but neither the artifact nor repository has tests or a changelog. For a database/query-builder library, the absence of both testing evidence and release documentation is a genuine maintenance and transparency gap.

Project backingcaution

The repository is owned by the user account collei rather than an organization. This provides direct project ownership but no organizational handoff or institutional backing to offset the concentrated maintainer base.

Release historycaution

The package is only 29 days old, with 9 releases and a median interval of about 2 days. This demonstrates active iteration but provides little evidence of long-term maintenance or release stability.

Repo bus factorcaution

One contributor made all 194 commits in the last 3 months, giving the repository a 100% top-contributor share. This creates a material single-maintainer continuity risk because the project is user-owned rather than organization-backed.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Al Ju

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
collei/collection
Version ^1.0

Weekly Downloads

Info

Last Published
18 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform