Package Health

felixdorn/php-color

Usable with caveats: the package is licensed, tested, non-deprecated, and backed by a matching repository, but it has had no release or commit activity for about two years. The single-maintainer project also lacks a package README and security policy.

Latest 1.0.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with roughly two years of inactivity and elevated abandonment risk.

Maintainerscaution

One registry maintainer is consistent with a small user-owned project, but it leaves limited visible publishing redundancy if that maintainer becomes inactive.

Package scaffoldingcaution

The published artifact has no README, which makes library integration less convenient, but the source repository contains a README and tests, and the package has a GitHub release for this version.

Project backingcaution

The registry namespace and repository owner match, and the repository is user-owned rather than organization-backed. This supports ownership consistency but offers limited institutional continuity.

Release historycaution

Only two releases were published, both on September 17, 2024, with no releases in the following 12 months. This is a meaningful sign of limited ongoing maintenance, although a small stable library may need few releases.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Félix Dorn

Direct Dependencies

DependencyLast ReleaseScore
savvot/random
Version ^v0.3.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform