Package Health

decodelabs/coercion

The package has clear licensing, documentation, repository ownership, and release notes for this version. Its workflow uses seven unpinned actions and the repository has no security policy, while recent release and commit activity is limited.

Latest v0.3.5PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has 28 releases since March 2022 and historically released frequently, but it has had no registry release in the last 12 months. That weakens evidence of current release maintenance.

Repo commit activitycaution

There were no commits and no active maintainers during the last three months, which weakens evidence of ongoing maintenance. The recent repository push shown by repository_archived partly offsets this concern but does not establish sustained activity.

Repo toolingcaution

The repository uses Composer build tooling, but no security-scanning tools were detected. The missing scanner is a maintenance and assurance gap, though it is not decisive by itself.

Security policycaution

The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled. This is a hygiene gap, not evidence that the package is unsafe.

Version stabilitycaution

Version v0.3.5 is not a prerelease, although the package remains below a stable major version. This is a modest maturity limitation rather than a severe concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tom Wright

Direct Dependencies

DependencyLast ReleaseScore
decodelabs/exceptional
Version ^0.6
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform