Package Health

goldfinch/basement

The small maintainer base and one recent commit leave limited backup if development stops. Clear licensing, a current stable release, recent publishing, and no install scripts provide useful reassurance.

Latest v2.0.8PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Maintainerscaution

Only one registry account can publish releases, which concentrates publishing responsibility; the linked repository is user-owned rather than organization-owned, so there is no provided backing evidence to offset this.

Project backingcaution

The repository owner is a user account rather than an organization, so the concentrated maintainer and commit activity is not offset by explicit organizational backing.

Repo bus factorcaution

All recent commits came from one contributor, leaving the project dependent on a single active maintainer and increasing abandonment risk.

Repo commit activitycaution

The repository had only 1 commit in the last 3 months from 1 active maintainer, indicating limited recent development activity despite the package having a recent release.

Repo popularitycaution

The repository has 0 stars and 0 forks, indicating little community adoption; popularity is supporting evidence only and does not outweigh the direct maintenance signals.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Art Karasev

Direct Dependencies

DependencyLast ReleaseScore
spatie/ignition
Version ^1.14
—
—
goldfinch/service
Version ^2.0
—
—
silverstripe/admin
Version ^2.0
—
—
silverstripe/framework
Version ^5.0
—
—
silverstripe/linkfield
Version ^3 || ^4
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform