Package Health

furikus/sfera

Its MIT declaration and lack of install scripts are positives. The repository has no security policy or security scanning, so adopting it carries avoidable transparency risk.

Latest v0.0.1PackagistPackagist

38%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

40

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

25

Health Score Breakdown

Package file treedanger

The artifact and linked repository each contain only composer.json, with no implementation files visible. That is unusually thin for a package described as sending logs to multiple destinations and makes the release difficult to assess.

Release historydanger

This release was published about 20 months ago, and it is the package's only release; there have been no releases in the last 12 months. That provides little evidence of active maintenance.

Package scaffoldingcaution

The package has no README, while tests and a changelog being absent are normal for a published artifact. Missing consumer documentation is still a meaningful gap for a library with multiple integrations.

Repo package mentioncaution

The linked repository is named artefact rather than sfera, and the collected data does not show the package name in its README. The repository may not actually be the source for this package.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures offer no external evidence of adoption or review.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jordi Boggiano

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0 || ^3.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform