Package Health

gcdtech/rhubarb.scaffold.speculator

The artifact includes a README, changelog, and Apache-2.0 license file, although the manifest labels the license proprietary. A single maintainer, no security policy, and minimal repository adoption add little confidence for long-term use.

Latest 1.0.0PackagistPackagist

12%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a dependency on the release.

Release historydanger

The package has only one release, 1.0.0, published about 9 years ago, with no releases in the last 12 months. This indicates abandonment rather than an actively maintained stable project.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last 3 months, and its last push was about 9 years ago. The organization backing does not compensate for the absence of observed maintenance.

Licensecaution

An Apache-2.0 license file is present in both the artifact and repository, but the manifest declares the package proprietary. The conflicting declarations reduce transparency even though the release is licensed.

Maintainerscaution

Only one registry account has publish access. The organization-owned repository makes a short registry maintainer list less concerning, but it does not offset the lack of recent release and commit activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andrew Cuthbert

Direct Dependencies

DependencyLast ReleaseScore
gcdtech/speculator
Version ^1.0.0
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform