Package Health

cupoftea/easycfg

The repository is clearly tied to the package and includes useful documentation and release notes. MIT licensing and no install-time scripts reduce adoption friction, but they do not offset the long maintenance gap.

Latest v1.1.2PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has had no release in nearly 11 years and no releases in the last 12 months, despite a short burst of four releases in 2015. This is strong evidence of abandonment risk.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last 3 months, consistent with the nearly 11-year release gap. This materially lowers confidence in ongoing maintenance.

Project backingcaution

The repository is owned by an individual rather than an organization, so there is no visible organizational backing to offset the single-maintainer context and prolonged inactivity.

Repo toolingcaution

Composer is used for the build, but no security-scanning tooling is present. The missing scanning is a hygiene gap rather than evidence of abandonment by itself.

Repository archivedcaution

The repository is not archived, which avoids an explicit abandonment marker, but its last push was nearly 11 years ago. The inactivity is already captured more directly by release and commit history.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

CupOfTea696

Direct Dependencies

DependencyLast ReleaseScore
cupoftea/package
Version ^1.2

Weekly Downloads

Info

Last Published
11 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform