Package Health

diegovilarinho/on-hand

It includes repository tests, an MIT license, and no install-time scripts, which reduce adoption friction. Its two runtime dependencies are explicit, but no security scanning or security policy is provided.

Latest 1.0.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has made only one release, on July 19, 2017, with no releases in the last 12 months. This leaves the release line about 9 years without evidence of ongoing maintenance.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last 3 months. Combined with the last repository push in 2017, this indicates a long-standing lack of observed maintenance capacity.

Project backingcaution

The repository is owned by an individual user rather than an organization. That does not establish abandonment by itself, but it provides less visible backing for a project with no recent activity.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. This is mildly reassuring about unresolved workload, but it does not compensate for the complete absence of recent commits.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tool is configured. The lack of scanning is a transparency and maintenance-hygiene gap, though it is less severe than the inactive release and commit history.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version ~5.4
—
—
optimus/architect
Version ~1.0
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform