Package Health

espressobytes/mergeconfigfiles

The six-file artifact has a focused README and no install-time scripts. Repository identity is supported by the README mention, but the project lacks security scanning and has little visible community support.

Latest 1.0.4PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historydanger

The latest release was published in June 2020, and there have been no releases in roughly six years. That strongly increases abandonment risk for a package with no newer maintenance evidence.

Repo commit activitydanger

The repository has recorded no commits or active maintainers in the last three months, consistent with its last push being roughly six years ago. The long-standing inactivity materially lowers confidence in ongoing maintenance.

Licensecaution

The manifest declares the package proprietary, with no detected license and no license file in either the artifact or repository. This creates a significant transparency and adoption concern for an open-source dependency.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide no meaningful external evidence of adoption or review.

Repo toolingcaution

Composer is used for the build, which is appropriate, but no security scanning tooling is present. For this small package that is a hygiene gap rather than evidence of an unsafe release.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tobias Bungers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform