Package Health

denosyscore/contracts

The package is still an early 0.x release, and all four workflow action references are unpinned. MIT licensing, a matching repository, Composer tooling, and Dependabot provide useful transparency, but no commits were recorded in about seven months.

Latest v0.2.3PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, while the last push was about seven months ago; this is a meaningful abandonment concern.

Release historycaution

All five releases arrived within roughly two days, and there has been no later release over about seven months; this suggests an immature or stalled release history.

Security policycaution

The repository has no security policy, which leaves vulnerability-reporting expectations unclear for a framework contracts package.

Version stabilitycaution

Version v0.2.3 is a non-stable-major 0.x release, so its interfaces may still change even though it is not marked as a prerelease.

Workflow auditcaution

Both workflows were fully analyzed with no dangerous audit findings, but all four action references are unpinned, leaving their versions exposed to upstream changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^2.0
—
—
psr/event-dispatcher
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform