Package Health

drupal/drupal-library-installer-plugin

Risky to adopt: the last release and repository update were in December 2015, with no commits in the past three months. The package is small and dependency-light, but it has no discovered license and shows little evidence of ongoing maintenance.

Latest 0.3PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has only three releases and none in the past 12 months; its latest release was in December 2015, indicating roughly ten years without a new release. This is a substantial abandonment risk despite the package's age and potentially stable scope.

Repo commit activitydanger

There were zero commits and zero active maintainers in the past three months. For a dependency last released roughly ten years ago, this strongly suggests maintenance has stopped.

Licensecaution

No declared license or license file was found in the package or repository. That creates a real adoption and legal-transparency concern for an open-source dependency.

Repo popularitycaution

The repository has only two stars and no forks, providing little evidence of a broad user or contributor community. Popularity is supporting evidence rather than decisive, but it offers no compensating maintenance signal.

Repo toolingcaution

Composer is used as a build tool, which fits the package's ecosystem, but no security-scanning tools are configured. The missing scanning is a hygiene gap, though it is less significant than the long-term inactivity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Allan Chappell

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
10 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform