Package Health

firehed/container

firehed/container is a mature, actively maintained package with a release history spanning over seven years, four releases in the last 12 months, a current stable version, and a recent repository push. The linked repository is clearly associated with the package, contains tests and substantial CI/static-analysis tooling, and has two active contributors, although activity is modest, ownership is concentrated, the repository has low adoption indicators, 17 open issues with little recent issue activity, and no security policy. The single registry maintainer is a manageable transparency and continuity concern for an individually owned project rather than evidence of abandonment. Overall, it appears suitable to depend on, with normal diligence around its small maintainer base and unresolved issue backlog.

Latest 1.2.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access. This is a continuity concern, but the individually owned repository and recent two-contributor activity provide some compensating evidence.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational handoff signal to offset the small maintainer base; however, two recent contributors and ongoing releases provide partial support.

Repo bus factorcaution

Two contributors were active in the last 3 months, but the top contributor made 80% of commits. This leaves maintenance concentrated in one person and creates some continuity risk.

Repo issue activitycaution

There are 17 open issues and 5 open pull requests, while the last month had no new or closed issues and only one merged pull request. This suggests an unresolved backlog and limited recent issue-management activity.

Repo popularitycaution

The repository has only 2 stars and 1 fork, indicating limited external adoption. Popularity is supporting evidence rather than a verdict, so this modestly reduces confidence but is not by itself a maintenance failure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eric Stern

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1 || ^2.0 || ^3.0
psr/container
Version ^1.0 || ^2.0
nikic/php-parser
Version ^5.0

Weekly Downloads

Info

Last Published
21 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform