Package Health

gourmet/dashboard

The package is explicitly alpha and has only three releases, while its repository has seen no push since February 2015. MIT licensing, a README, and tests improve transparency but do not offset the lack of ongoing maintenance.

Latest 0.2.0PackagistPackagist

35%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

58

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has only three releases, all clustered in 2014, with zero releases in the last 12 months and a package age of about 12 years. This is strong evidence of abandonment for a dependency.

Repository archiveddanger

The repository is not formally archived, but its last push was in February 2015, nearly 12 years before assessment. That observed inactivity is a substantial maintenance risk despite the repository remaining available.

Project backingcaution

The repository is owned by the gourmet organization, which provides some project backing. However, that administrative context does not compensate for the observed absence of release and commit activity.

Security policycaution

The repository has no security policy. This is a transparency and maintenance gap, though it is secondary to the much stronger evidence of prolonged inactivity.

Version stabilitycaution

Version 0.2.0 is not a stable major release, and the registry's latest version is 0.1.1, suggesting an immature or inconsistent release line. The lack of recent releases reinforces that concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jad Bitar

Direct Dependencies

DependencyLast ReleaseScore
leafo/scssphp
Version ~0.1
cakephp/cakephp
Version 3.0.*-dev
kriswallsmith/assetic
Version ~1.1
cakephp/plugin-installer
Version dev-master

Weekly Downloads

Info

Last Published
11 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform