Package Health

crustum/blazecast

Usable with caveats: it has frequent recent releases, an active-looking organization-backed repository, tests in the source repository, and no deprecation or archived status. However, zero commits in the last three months, a large runtime dependency set, and no security policy leave meaningful maintenance and transparency concerns.

Latest 0.4.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package declares 16 runtime dependencies for a WebSocket server plugin, including networking, Redis, authentication, and framework components. That breadth increases upgrade and compatibility maintenance burden, although it is consistent with the package's stated functionality.

Repo commit activitycaution

The repository records 0 commits and 0 active maintainers over the last three months. Despite the recent registry releases, this is a meaningful warning that current source maintenance may have paused or that releases may not reflect ongoing development.

Repo toolingcaution

The repository uses Composer, but no security scanning tools were detected. Build tooling is present, while the lack of automated security scanning leaves a transparency and maintenance gap for a network-facing plugin.

Security policycaution

No security policy was found in the repository. For a plugin that operates a WebSocket server and includes authentication and network-facing functionality, the absence of documented vulnerability reporting is a genuine transparency gap.

Version stabilitycaution

Version 0.4.0 is not a stable-major release, so the public API may still change before 1.0. It is not marked as a prerelease, which partly offsets the maturity concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
react/async
Version ^4.3
react/socket
Version ^1.14
crustum/rhythm
Version ^1.0
symfony/config
Version ^7.0
cakephp/cakephp
Version ^5.2

Weekly Downloads

Info

Last Published
7 days ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform