Package Health

fabiomattei/uglyduckling

Documentation, tests, and release notes are present, and the repository is still receiving commits. The project has no security policy and very little adoption, so future maintenance depends heavily on one person.

Latest 0.3.0PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has only three releases since May 2020 and none in the past 12 months; the latest registry release was about two years ago. This indicates a slow release cadence despite recent source activity.

Repo bus factorcaution

One contributor made 54 of 56 recent commits, or 96.4%, while the second made only two. The project is user-owned rather than organization-backed, so this concentration leaves maintenance heavily dependent on one person.

Repo popularitycaution

The repository has only three stars, zero forks, and two watchers. Popularity is supporting evidence rather than a verdict, but these numbers provide little outside evidence of broad adoption or review.

Repo toolingcaution

Composer is used for builds, but no security-scanning tooling was detected. This is a hygiene gap for a web framework, partially offset by the repository's active commit history and test coverage.

Security policycaution

The repository has no security policy. For a web application framework, that weakens the transparency and vulnerability-reporting process, though it does not by itself show abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Fabio Mattei

Direct Dependencies

DependencyLast ReleaseScore
wixel/gump
Version dev-master
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform