Package Health

decole/yr-no

The README and release notes provide useful integration context, and the repository is not archived. However, the project lacks a security policy and automated security scanning, making an aging client harder to trust and maintain.

Latest 1.0.1PackagistPackagist

46%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This is the package's only release, published nearly five years ago, with no releases in the last 12 months. That strongly raises abandonment and compatibility risk despite the repository remaining available.

Repo popularitycaution

The repository has zero stars, one fork, and one watcher, providing little independent evidence of adoption or community support. Popularity is only supporting evidence, so this modestly reinforces the maintenance concern.

Repo toolingcaution

Composer is used for builds, but no security-scanning tools were detected. For a client library that handles remote API responses, this is a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy, leaving no documented path for reporting vulnerabilities. This is a hygiene concern, though it is less significant than the lack of recent maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Galochkin Sergey

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^6.4||^7.0

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform