Package Health

dealnews/test-helpers

This is a generally healthy, usable test-helper package: it has a clear BSD-3-Clause license, complete source and test files, stable releases, no deprecation, no install-time lifecycle scripts, and an organization-backed repository that is not archived. The main concerns are limited ecosystem adoption, no recorded commit activity or active maintainers in the last 3 months despite a recent release, and incomplete repository security hygiene (no security policy and no top-level workflow permissions). These issues warrant monitoring, but the package remains a reasonable dependency for projects that accept its small contributor and adoption footprint.

Latest 2.1.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares only three runtime dependencies, keeping the dependency surface modest, although PHPUnit as a runtime dependency is notable for a test-helper library and should be checked against the consuming project's setup.

Repo commit activitycaution

No commits and no active maintainers were recorded in the last 3 months, despite the latest registry release being recent. This creates a meaningful maintenance-continuity concern, although the recent release and non-archived repository provide partial counterevidence.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. A clean tracker is not inherently negative, but it provides little evidence of an active external maintenance community.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 2 watchers. This is weak supporting evidence and suggests limited external adoption, though popularity alone does not make a small maintained package unsafe.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The absence of scanning lowers repository security hygiene, while the package's coherent CI and test structure provide some compensation.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
phpunit/phpunit
Version ^11.0
—
—
guzzlehttp/guzzle
Version ^7.15.2 || ^8.1
—
—

Weekly Downloads

Info

Last Published
14 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform