Package Health

componenta/skeleton

The release is well documented, tested, licensed, and backed by a matching organization repository. Maintenance is active but concentrated in one contributor, while workflow references are not pinned and no security scanning is configured.

Latest v5.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Health Score Breakdown

Repo bus factorcaution

Only one contributor made all 16 recent commits, leaving maintenance dependent on a single person; organization backing provides some handoff capacity but does not remove the concentration risk.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured, leaving a meaningful project-hygiene gap.

Workflow auditcaution

The workflow was fully analyzed, uses read-only permissions, and has no audit findings, but all 3 action references are unpinned, reducing build reproducibility and update integrity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
componenta/di
Version ^5.0.3
psr/container
Version ^2.0
componenta/app
Version ^5.0.0
componenta/http
Version ^1.0
symfony/console
Version ^7.4 || ^8.0

Weekly Downloads

Info

Last Published
4 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform