Package Health

devshop/composer-common

The package is small and clearly documented, with tests, a changelog, and an MIT license. Its last release was nearly six years ago, and repository activity has stopped, while the current version remains an alpha.

Latest 1.7.0-alpha4PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historydanger

The package has five releases but none in the last 12 months; its latest release was nearly six years ago, which is a substantial maintenance concern.

Dependency profilecaution

The package declares four runtime dependencies, including GitHub API and Git stream-wrapper components; this is a meaningful dependency surface for a small utility package, but not severe on its own.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months, consistent with a repository that has seen little recent maintenance.

Repo issue activitycaution

There were no new or merged pull requests and no issue activity in the last month; this adds to the evidence of inactivity, although open-issue data is unavailable.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are reported; the missing scanning is a modest repository hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jon Pugh
DevShop Community

Direct Dependencies

DependencyLast ReleaseScore
consolidation/robo
Version ^1.0
knplabs/github-api
Version ^1.0
teqneers/php-stream-wrapper-for-git
Version ^2.0@dev

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform