Package Health

geekmusclay/framework

Latest 0.3.1PackagistPackagist

58%

Total Score

caution

Usable with caveats: release activity stopped over two years ago, despite solid package structure and tests.

Health Score Breakdown

Project backingcaution

The registry namespace and repository owner match, but the owner is an individual account rather than an organization. That is consistent ownership, though it indicates a thin backing structure.

Release historycaution

The package has seven releases, but none in the last 12 months and the latest registry release was over two years ago. Earlier releases were reasonably spaced, which partly offsets but does not remove the current maintenance concern.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, while the last recorded push was over two years ago. This is a meaningful abandonment risk.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, providing little evidence of a broad user or contributor community. Low popularity is supporting evidence rather than a verdict by itself.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That leaves a gap in automated security oversight for a framework package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

geekmusclay

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.4
—
—
geekmusclay/orm
Version ^0.4.0
—
—
guzzlehttp/psr7
Version ^2.4
—
—
geekmusclay/router
Version ^0.6.0
—
—
geekmusclay/di-container
Version ^0.1
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform