Package Health

everyworkflow/eav-bundle

The MIT license, tests, and organization-owned repository provide useful foundations. The missing README and absent security policy reduce transparency for a library.

Latest v0.1.0PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

This package has only one release, published about four years ago, with no releases in the last 12 months. That is strong evidence of limited maintenance, though it is not proof the code is unusable.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months, consistent with a repository that has seen no push for about three years. This materially raises abandonment risk.

Package scaffoldingcaution

The package and repository include tests, and this version has a GitHub release. The missing README reduces library consumer guidance, while the absent changelog is normal packaging practice and not a gap by itself.

Repo popularitycaution

The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these very low engagement levels provide no meaningful community safety net.

Repo toolingcaution

Composer is used as a build tool, which fits this PHP package. No repository security-scanning tool was detected, leaving a modest hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

EveryWorkflow

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version ^2.55
—
—
everyworkflow/mongo-bundle
Version dev-main
—
—
everyworkflow/data-form-bundle
Version dev-main
—
—
everyworkflow/data-grid-bundle
Version dev-main
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform