Package Health

ernestdefoe/picks

Healthy and actively maintained, with a clear license, tests, matching repository, and recent commit activity. The main caveats are a small maintainer base, no security policy or security scanning, and a workflow with write permissions.

Latest 2.6.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a genuine publishing continuity concern for a user-owned project, although repository activity shows another active contributor.

Project backingcaution

The registry namespace and repository are owned by the same individual user rather than an organization, so there is no organizational backing to offset the small maintainer base.

Repo bus factorcaution

Commit activity is evenly split between two contributors, so no single contributor dominates the recent history; the small total contributor base still leaves limited redundancy.

Repo popularitycaution

The repository has zero stars, forks, and watchers, limiting external validation and community support; this is supporting evidence rather than a decisive health failure.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured, leaving a security-maintenance gap that is relevant for a package with application and frontend code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ernestdefoe

Direct Dependencies

DependencyLast ReleaseScore
flarum/core
Version ^2.0.0-beta.8
guzzlehttp/guzzle
Version ^7.0
intervention/image
Version ^3.0

Weekly Downloads

Info

Last Published
8 days ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform