Package Health

dmitryrechkin/php-phpunit-bootstrap

The small artifact has no tests, changelog, README, or repository security scanning, so consumer guidance and maintenance checks are limited. Its single-person ownership and long release interval add uncertainty, although the repository is present, unarchived, and the package is not deprecated.

Latest 1.0.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Licensecaution

The package declares AGPL-3.0-only, while the artifact license file was detected as GPL-3.0; the presence of license files is positive, but the mismatch creates licensing uncertainty.

Package scaffoldingcaution

The artifact contains no README, tests, or changelog. Missing tests and changelog are normal for a published artifact, while the missing README is a minor usability and transparency gap for a command-line helper.

Release historycaution

Only two releases exist since September 2022, with a median interval of about 3 years; the release in the last 12 months is a partial counterweight but does not show a mature cadence.

Repo commit activitycaution

The repository had no commits and no active maintainers in the last 3 months. Its push date matches the latest release, but there is no evidence of ongoing development afterward.

Repo toolingcaution

Composer is used for build and dependency management, which is positive, but the repository reports no security-scanning tools, leaving a modest maintenance-hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dmitry Rechkin

Direct Dependencies

DependencyLast ReleaseScore
phpunit/phpunit
Version ^9.5.10
—
—
vlucas/phpdotenv
Version ^5.4
—
—

Weekly Downloads

Info

Last Published
9 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform