Package Health

escsrl/repository

Its compact source tree includes a changelog and a matching organization-owned repository. The long period without releases or commits, plus absent tests and security scanning, makes future fixes and compatibility support uncertain.

Latest 1.1.0PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historydanger

The latest release was published in December 2020, with no releases in the following five years and nine months. This is strong evidence of abandonment risk, although the package is not marked deprecated or archived.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with the release gap and materially increasing abandonment risk.

Dependency profilecaution

The package declares ten runtime dependencies, including framework and extension requirements, creating a relatively broad compatibility surface. The signal does not show these dependencies are unsafe or unmanaged, so this is only a modest concern.

Maintainerscaution

One registry publishing account is listed, but this is administrative access information rather than evidence of active maintenance. The organization-owned project backing provides some context but does not compensate for the inactivity.

Package scaffoldingcaution

The package includes a changelog, and the absence of tests is normal for a published artifact. However, the missing README reduces consumer guidance for this PHP library.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Veronica Lupo Pasini

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^2.7
—
—
nesbot/carbon
Version ^2.27
—
—
beberlei/assert
Version ^3.2
—
—
symfony/security-bundle
Version ^5.1
—
—
symfony/serializer-pack
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform