Package Health

doubleleft/hook

It includes a README, tests, release notes, and an MIT license. Organization backing and a post-install script provide some context, but the narrow release history and aging codebase limit confidence in continued support.

Latest v0.4.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

Only two releases exist, with none in the last 12 months; the latest registry release was about 4 years ago and release intervals are very long. This is strong evidence of limited ongoing maintenance.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last 3 months, while its last push was about 9 years ago. The release history does not compensate for this long period of source inactivity.

Lifecycle scriptscaution

A post-install Composer lifecycle script runs during installation. This adds operational and supply-chain exposure that developers should understand, although the signal alone is not evidence that the package is unsafe.

Security policycaution

The linked repository has no security policy. For a backend service handling authentication, data, and credentials, this weakens vulnerability-reporting transparency.

Version stabilitycaution

v0.4.0 is not marked as a prerelease, so the assessed release is presented as a normal stable release. Its pre-1.0 major version still indicates a less mature compatibility commitment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Endel Dreyer

Direct Dependencies

DependencyLast ReleaseScore
endel/slim
Version dev-master
—
—
react/socket
Version 0.4.*
—
—
doctrine/dbal
Version 2.*
—
—
cboden/ratchet
Version 0.3.*
—
—
patchwork/utf8
Version ~1.2
—
—

Weekly Downloads

Info

Last Published
11 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform