Package Health

harvestcloud/core-bundle

The package includes a README, repository tests, and an MIT license. Its source project has no security policy or scanning, adding transparency concerns to the otherwise limited maintenance evidence.

Latest v0.1.5PackagistPackagist

35%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has only four releases, all clustered in February 2013, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency released as v0.1.5.

Repository archiveddanger

The repository is not formally archived, but it was last pushed in April 2014—more than 12 years before this assessment. The unarchived status does not compensate for the long period without observed activity.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, and no open issues or pull requests. This is consistent with an inactive project, though issue counts alone are weaker evidence than release and commit history.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Although this can occur with subpackages, the missing reference makes package-to-source ownership less transparent.

Repo toolingcaution

Composer is used for the build, but no security-scanning tooling was detected. This does not prove unsafe dependencies, but it reduces evidence of ongoing maintenance hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
13 years ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform