Package Health

fabricate/sketches

The MIT license, matching repository, and absence of install-time scripts reduce adoption friction. Its short history and concentrated activity leave limited evidence of durable maintenance, while the missing README and security policy reduce transparency.

Latest v0.7.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Package scaffoldingcaution

The published artifact has no README, and the repository also reports no tests or changelog. Missing tests and changelog are normal for published artifacts, but the absent README weakens consumer documentation for this library.

Release historycaution

The package is only 51 days old with two releases, about 10 days apart. That shows initial activity but provides little evidence of sustained maintenance.

Repo bus factorcaution

One contributor made 100% of the recent commits. Organization backing provides some handoff capacity, but no second active contributor is evidenced.

Repo commit activitycaution

Only three commits were recorded in the last three months, all from one active maintainer. For a package this new, that is limited maintenance evidence rather than proof of abandonment.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing scanning evidence is a modest transparency and maintenance concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Angel Gonzalez

Direct Dependencies

DependencyLast ReleaseScore
symfony/finder
Version ^7.4.0 || ^8.0.0
symfony/console
Version ^7.4.0 || ^8.0.0
fabricate/console
Version ^0.7.0
fabricate/pipeline
Version ^0.7.0
fabricate/contracts
Version ^0.7.0

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform