Package Health

futuretek/yii2-shared

Recent releases and a matching Apache-2.0 license provide useful stability. The small codebase has limited validation and security-process evidence, reducing long-term assurance.

Latest 4.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package scaffoldingcaution

The artifact has no README, tests, or changelog, while the repository also reports no tests or changelog. Missing tests and project documentation reduce transparency for a reusable library, although their absence in the published artifact can be normal.

Repo bus factorcaution

All recent activity comes from one contributor, with that contributor responsible for 100% of the single recent commit. Organization backing provides some handoff capacity, but observed maintenance remains concentrated.

Repo commit activitycaution

The repository had one commit in the last 3 months, showing recent activity but at a low volume. This supports maintenance continuity without demonstrating a strong development pace.

Repo toolingcaution

Composer is used for builds, but no security scanning tools were detected. Build tooling is appropriate, while the missing security tooling leaves a modest assurance gap.

Security policycaution

The repository has no security policy. For a reusable library this makes vulnerability reporting and maintainer response expectations less transparent.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Lukas Cerny

Direct Dependencies

DependencyLast ReleaseScore
endroid/qr-code
Version ^6.0
giggsey/libphonenumber-for-php
Version ^8.12.35

Weekly Downloads

Info

Last Published
1 month ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform