Package Health

guanguans/music-php

The repository has tests, release notes, security scanning, and a security policy. Workflow checks need attention, and the package-to-repository naming mismatch reduces transparency; the recent work is concentrated in one maintainer.

Latest 7.1.13PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

Post-install and post-update scripts run during Composer operations, adding execution surface for consumers. No provided signal shows these scripts are unsafe, so this is a limited supply-chain concern rather than a severe risk.

Project backingcaution

The source repository is owned by a user rather than an organization, so the concentrated recent contribution profile is not offset by clear organizational handoff capacity.

Repo bus factorcaution

All recent commits come from one contributor with a 100% share, creating a meaningful continuity risk for a user-owned project.

Repo commit activitycaution

Only 2 commits were made in the last 3 months, with one active maintainer, so current maintenance activity is thin despite frequent registry releases.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, making the package-to-source relationship less transparent even though the repository appears related by owner and content.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

guanguans

Direct Dependencies

DependencyLast ReleaseScore
wikimedia/composer-merge-plugin
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
13 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform