Package Health

dotkernel/dot-authentication-service

It has clear documentation, MIT licensing, release notes, and identifiable organization backing. Future fixes may be limited because the project is maintained only for security and has gone over two years without a release.

Latest 2.9.2PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Package scaffoldingcaution

The package includes a substantial README, changelog, and release notes for version 2.9.2, which supports consumer understanding and release transparency. The README explicitly places the project in security-only maintenance mode, limiting expectations for new development.

Release historycaution

The package has existed since 2017 with nine releases, but the latest release was over two years ago and there were no releases in the last 12 months. This indicates materially reduced maintenance activity.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. Combined with the long release gap, this is a meaningful abandonment concern.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest hygiene gap, partly offset by the repository's documented security policy.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

DotKernel Team

Direct Dependencies

DependencyLast ReleaseScore
psr/http-message
Version ^1.0 || 2.0
laminas/laminas-db
Version ^2.15.0
laminas/laminas-session
Version ^2.12.1
laminas/laminas-hydrator
Version ^4.3.1
laminas/laminas-psr7bridge
Version ^1.6.0

Weekly Downloads

Info

Last Published
2 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform