Package Health

gmta/composer-velocita

The MIT license, release notes, repository tests, and matching source make the package transparent. Its small maintainer base and absent security tooling add modest ongoing risk.

Latest 6.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access. That is a thin publishing base for a package with no recent activity, increasing continuity risk, although it does not by itself establish poor project backing.

Project backingcaution

The registry namespace and repository owner match, and the owner is a user account rather than an organization. This supports repository identity but offers limited evidence of organizational continuity.

Release historycaution

The package has 13 releases but none in the last 12 months, and its latest release was over two years ago. This points to a materially increased maintenance and abandonment risk.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, consistent with the package's long release gap and indicating substantially reduced maintenance capacity.

Repo toolingcaution

The repository uses Composer build tooling, but no security-scanning tools were detected. For a Composer plugin involved in package downloads, this leaves a meaningful security-hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jelle Raaijmakers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform