Package Health

davwheat/flarum-ext-share

The MIT license, focused dependency set, matching repository, and release notes make its contents easy to understand. A single maintainer, small user footprint, no security policy, and an unpinned workflow reference leave limited assurance for future upkeep.

Latest v1.1.0PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

70

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was published on February 7, 2023, and there have been no releases in the last 12 months. This indicates substantially reduced maintenance activity for a package that has existed for nearly five years.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months, with the last push in March 2023. That prolonged inactivity raises abandonment risk.

Maintainerscaution

Only one registry maintainer is listed, and the project backing identifies an individual rather than an organization. This leaves little visible redundancy if the maintainer becomes unavailable.

Repo popularitycaution

The repository has 2 stars, 1 fork, and 1 watcher. Popularity is not required for a healthy small extension, but these figures provide little supporting evidence of broad use or community resilience.

Security policycaution

The linked repository has no security policy. That is a transparency and vulnerability-reporting gap, although it does not by itself show that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

David Wheatley

Direct Dependencies

DependencyLast ReleaseScore
flarum/core
Version ^1.2.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform