Package Health

componenta/cqrs-app

The release includes tests, a substantial README, and GitHub release notes. It has no install scripts, is not deprecated, and is backed by an organization.

Latest v5.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

One contributor made 100% of the 52 recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown to reduce the immediate bus-factor concern.

Repo commit activitycaution

The repository had 52 commits in the last 3 months, showing strong recent activity. However, all activity came from one maintainer, which leaves continuity dependent on a single contributor.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and assurance gap rather than evidence of unsafe code.

Security policycaution

The repository has no security policy. That leaves vulnerability-reporting and response expectations undocumented, a minor transparency concern for a dependency.

Workflow auditcaution

Both workflows use read-only permissions and the audit found no injection or high-severity findings. However, all 8 action references are unpinned, weakening build reproducibility and supply-chain integrity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
componenta/di
Version ^5.0.3
—
—
psr/container
Version ^2.0
—
—
componenta/app
Version ^5.0.0
—
—
componenta/cqrs
Version ^4.0.0
—
—
componenta/config
Version ^3.0.0
—
—

Weekly Downloads

Info

Last Published
5 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform