Package Health

dragonzap/subtitle-generator

It has a clear GPL license, a substantial README, and release notes, but only one registry maintainer and no security scanning. The install hook, credential-named file, and inactive repository add maintenance and change-control risk.

Latest v1.0.2PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has had only 3 releases, all clustered within about 1 day, and none in the last 12 months; the latest release is now about 2 years and 8 months old. This provides little evidence of ongoing maintenance.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, with its last push about 2 years and 8 months ago. This is strong evidence that maintenance has stopped or greatly slowed.

Dependency profilecaution

The package has 3 runtime dependencies, including Laravel and two Google Cloud clients, so adoption brings a meaningful dependency surface for a small library.

Lifecycle scriptscaution

A pre-install-cmd script runs during installation, increasing the package's change-control and supply-chain exposure compared with a package without install-time execution.

Maintainerscaution

Only one registry account has publish access. This is a thin publishing base and leaves little redundancy if that maintainer becomes unavailable.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dragon Zap Publishing

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version ^9.0|^10.0
—
—
google/cloud-speech
Version ^1.0
—
—
google/cloud-storage
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform