Package Health

ernestdefoe/google-fonts

Healthy and suitable to install, with modest transparency and security-process gaps. It is actively maintained, has two recent contributors, and is not deprecated or archived; the main concerns are no tests, no security policy, and a workflow with write permissions.

Latest 0.2.4PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health checks

Maintainerscaution

Only one registry publisher is listed, which is a limited publishing backup for a user-owned project. Repository activity from a second contributor provides some compensating maintenance evidence.

Package scaffoldingcaution

A substantial README and GitHub Releases are present, but neither the package nor repository includes tests or a changelog. The missing tests reduce confidence in maintenance quality, while releases partly compensate for the missing changelog.

Project backingcaution

The registry namespace and repository are owned by the same individual, so the package has direct ownership alignment but no organization-level backing or evident handoff capacity.

Repo popularitycaution

The repository has one star and no forks or watchers, indicating little external adoption or review. Popularity is supporting evidence only, so this lowers confidence modestly rather than making the package unfit.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. The build setup is adequate for the package, while the missing scanning is a modest process gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ernestdefoe

Direct Dependencies

DependencyLast ReleaseScore
flarum/core
Version ^2.0

Weekly Downloads

Info

Last Published
4 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform