Package Health

ernestdefoe/chronicle

The package has clear documentation, release notes, a matching source repository, and a permissive MIT license. Its only release is brand new, so maintenance history is unproven; the missing security policy and repository scanning add modest transparency concerns.

Latest 1.0.0PackagistPackagist

64%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package was first and last released on the same day, with only one release and no established release cadence. This is expected for a new project but leaves maturity and maintenance unproven.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That is a modest repository hygiene gap rather than evidence of unsafe code.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.

Workflow auditcaution

Both workflows were analyzed without audit findings or untrusted checkouts, but one workflow grants top-level write permissions, which is broader than necessary and mildly weakens workflow hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ernest Defoe

Direct Dependencies

DependencyLast ReleaseScore
flarum/core
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
17 hours ago
Created
17 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform