Package Health

frzb/php-doc-reader

The package has a clear MIT license, tests, release notes, and no install-time scripts. Its very small project footprint, absent recent activity, repository naming mismatch, and weak workflow pinning reduce confidence in ongoing maintenance.

Latest v2.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

The package has five releases, but none in the last 12 months and the latest release was on December 26, 2023, indicating likely inactive maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current maintenance.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, so the linked source may not clearly belong to this release.

Workflow auditcaution

All six workflow action references are unpinned, and a high-confidence archived-action finding remains; the cache-poisoning findings are low confidence and therefore only hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mykhailo Shtanko

Direct Dependencies

DependencyLast ReleaseScore
fp4php/functional
Version ^6.0
doctrine/annotations
Version ^1.14
symfony/framework-bundle
Version ^6.0|^7.0
friendsofphp/php-cs-fixer
Version ^3.42
frzb/dependency-injection
Version ^2.0

Weekly Downloads

Info

Last Published
2 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform