Package Health

ecodenl/pico-wrapper

Wrapper for the PICO web service

Latest v1.0.1PackagistPackagist

42%

Total Score

unhealthy

Risky: no releases or commits for nearly four years, indicating likely abandonment.

Health Score Breakdown

Release historydanger

The package has only two releases, both from August 2022, with no release in nearly four years. That is strong evidence of stalled maintenance for a dependency that may need compatibility or security updates.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no recent activity to offset the abandonment risk.

Maintainerscaution

Only one account has registry publish access, which leaves little apparent publishing redundancy. The organization-owned repository provides some project backing, so this is a caution rather than a severe risk by itself.

Repo toolingcaution

Composer is used for the build, but no security scanning tools are present. This is a modest transparency and maintenance gap, not evidence that the release is unsafe on its own.

Security policycaution

The linked repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This matters more because the project also has no recent maintenance activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Patrick van Kouteren

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^6.3.1|^7.4.5
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform