Package Health

danccas/nexus

The dependency set is small, and the release has notes plus a matching source repository. The declared MIT license conflicts with the GPL-3.0 license found in the artifact, while no commits or active maintainers were observed in the last three months.

Latest v1.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

This is the package's only release, published about 1 year and 3 months ago, with no releases in the last 12 months. That leaves little evidence of sustained maintenance.

Repo commit activitydanger

The repository had 0 commits and 0 active maintainers in the last three months, reinforcing the abandonment concern from the single-release history.

Licensecaution

The artifact contains a license file, but it identifies GPL-3.0 while the manifest declares MIT. The package is licensed, yet the mismatch creates a material adoption and compliance concern.

Lifecycle scriptscaution

A post-update-cmd lifecycle script runs during dependency updates. This is a supply-chain hygiene concern because package installation or updates can execute publisher-controlled behavior.

Repo popularitycaution

The repository has 0 stars, 0 forks, and 1 watcher. This provides little community backing, but popularity is supporting evidence rather than a verdict.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
setasign/fpdi
Version ^2.0
—
—
tecnickcom/tcpdf
Version 6.3.*
—
—
bacon/bacon-qr-code
Version 2.0.8
—
—
danccas/nexus-framework
Version ^1.0.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform