Package Health

ernestdefoe/garrison

Usable with caveats: the release is licensed, documented, tested, and actively being published, but the project is only one day old and has no recorded three-month commit activity or community adoption. Treat it as an early-stage dependency until a longer maintenance track record emerges.

Latest v1.3.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health checks

Release historycaution

The package is only 1 day old, with 9 releases compressed into roughly 25 hours. That shows active initial development but provides almost no long-term maintenance evidence.

Repo commit activitycaution

No commits or active maintainers were recorded in the preceding 3 months. Because the repository is only 1 day old, this mainly reflects insufficient history rather than demonstrated abandonment, but it remains a material maturity gap.

Repo popularitycaution

The repository has zero stars, forks, and watchers. A new package need not be popular, but these counters provide no external adoption or community support evidence.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest supply-chain transparency gap, partly offset by the repository's CI and other workflow checks.

Security policycaution

The repository has no SECURITY.md or other detected security policy. That weakens vulnerability-reporting transparency, though it is not by itself evidence that the release is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ernestdefoe

Direct Dependencies

DependencyLast ReleaseScore
flarum/core
Version ^2.0

Weekly Downloads

Info

Last Published
1 day ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform