Package Health

heptacom/jane-php

Its documentation, tests, licensing, and organization backing are solid. Workflow action pinning is weak, and the source does not explicitly mention this package.

Latest v6.2.4PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest registry release was published in March 2021, with no releases in the following five years. That long gap is strong evidence of abandonment risk despite the package having a substantial release history.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months, consistent with the multi-year release gap. This materially increases abandonment risk.

Repo package mentioncaution

The repository name does not match this package and its README does not mention it. The repository tree and description indicate a multi-library monorepo, which makes the mismatch understandable but still leaves package ownership less explicit.

Repo popularitycaution

The repository has zero stars and watchers and one fork, offering little supporting evidence of broad community use. Popularity is only supporting evidence, so this is a minor concern rather than a primary verdict.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a hygiene gap, not evidence that the release is unsafe by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joel Wurtz
Baptiste Leduc

Direct Dependencies

DependencyLast ReleaseScore
league/uri
Version ^6.0
symfony/yaml
Version ~4.4.9 || ^5.0
symfony/string
Version ^5.0
psr/http-client
Version ^1.0
symfony/console
Version ^4.4 || ^5.0

Weekly Downloads

Info

Last Published
5 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform