Package Health

darkgoldblade01/velocify

Risky to adopt for a new dependency: the last release was about 9 years ago and the repository has had no commits for roughly 6 years. Tests, a usable README, and no deprecation or archive status help, but the package has no license and shows little ongoing activity.

Latest v0.0.2.2PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historydanger

The package has had only four releases, all clustered in 2017, with no release in about 9 years. That strongly suggests abandonment, although the package is not marked deprecated.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers over the last 3 months, consistent with the roughly 6-year gap since the last push. This is the main abandonment concern.

Dependency profilecaution

Seven runtime dependencies, including several PHP extensions and two libraries, create some maintenance surface for an old package, but the profile is not unusually large or opaque.

Licensecaution

Neither a declared license nor a license file was found in the package or repository. This creates a real adoption and redistribution concern.

Maintainerscaution

One registry account has publish access. This is a modest bus-factor concern for a user-owned project, though registry access alone does not establish whether the project is actively maintained.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Brian Logan

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version ^1.22
—
—
guzzlehttp/guzzle
Version ~6.0
—
—
suramon/simple-xml-reader
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform