Package Health

depa/depa-tooling

The package is clearly identified, licensed, and avoids install-time scripts. Its single maintainer and minimal documentation reduce resilience, while the repository has been inactive since late 2020.

Latest v1.0.3PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has had no release in nearly six years: its latest release was in November 2020, with zero releases in the last 12 months. Four releases show an established history but do not offset the prolonged inactivity.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating a high abandonment risk.

Maintainerscaution

Only one registry account can publish releases, which limits publishing resilience. The organization-owned repository provides some backing and makes a short registry maintainer list less concerning.

Package scaffoldingcaution

The artifact includes a README, but it is only 14 characters long and provides little consumer guidance. Missing tests and a changelog are normal packaging practice, while the GitHub release provides some release transparency.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mirko Fenrich

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^4.4
—
—
laminas/laminas-db
Version ^2.11
—
—
laminas/laminas-code
Version ^3.4
—
—
composer/package-versions-deprecated
Version 1.11.99.1
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform