Package Health

contributte/framex

The repository includes tests, release notes, an MIT license, and organization backing, which support dependable use. GitHub Actions are not pinned, and recent commit activity is absent despite a release this year.

Latest v0.3.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package is about 3 years old but has only 3 releases, with a median interval of about 394 days and 1 release in the last 12 months. This indicates a slow maintenance cadence, though the latest release was published recently.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months. That is a meaningful maintenance warning, especially alongside the package's generally slow release cadence.

Repo toolingcaution

The project uses Composer and Make, but no security scanning tool was detected. The missing scanner is a hygiene gap, not evidence that the release is unsafe by itself.

Version stabilitycaution

The latest release is v0.3.0 and is not marked as a prerelease, but the 0.x major version signals an API that may still change. This is a moderate adoption consideration rather than an abandonment concern.

Workflow auditcaution

All 4 workflows were analyzed with no reported audit findings, no untrusted checkouts, and no script injection. However, all 8 analyzed action references are unpinned, leaving avoidable build-integrity exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Milan Felix Šulc

Direct Dependencies

DependencyLast ReleaseScore
nette/utils
Version ^4.0.0
—
—
psr/container
Version ^2.0.2
—
—
clue/framework-x
Version ~0.17.0
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform