Package Health

enthusiast/worker-template

This is a usable but relatively immature package with strong recent publishing activity, a stable release line, an active unarchived repository, and no install-time scripts. However, the package has no license file or declaration, no tests or changelog, a single registry maintainer, no security scanning or security policy, and a very small repository with no visible community activity; the unusually short median release interval also warrants caution about release discipline. Dependence may be reasonable if the package fits your needs and you can review its source, but it lacks several transparency and assurance signals expected of a mature dependency.

Latest 1.2.9PackagistPackagist

63%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package declares nine runtime dependencies, including several PHP extensions and telemetry, Kafka, Redis, and framework components; this is a relatively broad integration surface that can increase compatibility and operational maintenance burden.

Licensecaution

Neither a declared license nor a license file was found, leaving the legal terms for reuse unclear; this is a genuine transparency concern.

Maintainerscaution

Only one account has registry publish access. That is a concentration risk, although this administrative signal does not by itself establish poor maintenance activity.

Package scaffoldingcaution

The artifact includes a substantive README, but it has no tests and no changelog, and the repository also has no tests or changelog. For a worker and instrumentation library, the lack of executable regression coverage is a meaningful maintenance and compatibility gap.

Project backingcaution

The source repository is owned by an individual user rather than an organization, so there is no visible organizational backing or redundancy to offset the single-maintainer concentration.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Konstantin Popov

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0 || ^3.0
enqueue/rdkafka
Version ^0.10.27
open-telemetry/api
Version ^1.0
open-telemetry/sdk
Version ^1.14
yiisoft/yii-console
Version ^2.4

Weekly Downloads

Info

Last Published
10 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform