Package Health

deter-consulting/lexoffice-bundle

The MIT licensing and correctly matched repository provide basic transparency, but the package offers almost no consumer documentation. Its very small contributor footprint and lack of maintenance activity make future compatibility and fixes uncertain.

Latest 0.0.4PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published nearly three years ago, and there were no releases in the last 12 months. This is strong evidence of abandonment risk despite the package having three releases overall.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months, consistent with the nearly three-year gap since the last repository push. This materially increases abandonment risk.

Package scaffoldingcaution

A README is present, but it contains only 18 characters and offers little integration guidance. Missing tests and a changelog are normal for a published artifact and are not concerns here.

Project backingcaution

The repository is owned by a user account rather than an organization, and the registry has one maintainer. This indicates a thin visible ownership base, with no organizational backing shown by the provided data.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy small package, but these figures provide no supporting evidence of community adoption.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Max Deter

Direct Dependencies

DependencyLast ReleaseScore
symfony/symfony
Version 6.*
guzzlehttp/guzzle
Version 7.*

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform