Package Health

dhiraj/yii2-ffmpeg-static

It ships the expected platform binaries under an MIT license and has no install-time scripts, but provides little consumer documentation. The single-user project has no security scanning or policy, leaving maintenance and review capacity thin.

Latest 0.2PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has only two releases, with the latest published in December 2017 and none in the last 12 months. This is strong evidence of abandonment for a package distributing platform binaries.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since December 2017.

Maintainerscaution

One registry maintainer is reasonable for a user-owned project, but it provides little redundancy when the repository also shows no recent activity.

Package scaffoldingcaution

The artifact has no README, while tests and a changelog are not expected in a package that mainly ships compiled platform binaries. The missing README is a minor consumer-documentation gap.

Repo popularitycaution

The repository has only 2 stars and no forks, offering little supporting evidence of broad review or an active user community. Popularity is supporting evidence, so this reinforces rather than determines the maintenance concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dhiraj Gupta

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform