Package Health

herbiez/webwechat

The MIT license and Composer-based structure are clear, but the 38-character README, absent tests, and no security policy leave little guidance or assurance. Its ten runtime dependencies also increase upkeep burden for a package with no development activity.

Latest 0.1.0PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

56

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

This is the package's only release, published over 9 years ago, with no releases in the last 12 months; that is strong evidence of abandonment risk.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last 3 months, reinforcing the release-history evidence that maintenance has stopped.

Dependency profilecaution

Ten runtime dependencies, including several framework and utility packages, create a meaningful maintenance surface for a project that has not released since 2017.

Package scaffoldingcaution

A README and release notes exist, but the README is only 38 characters and the package and repository have no tests or changelog. The release notes provide a small amount of documentation for this version.

Project backingcaution

The repository owner is an individual user rather than an organization, so there is no observed organizational backing to offset the single-maintainer and inactivity concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Herbie

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version ^1.21
—
—
pimple/pimple
Version ^3.0
—
—
endroid/qrcode
Version ^1.7
—
—
symfony/console
Version 3.*
—
—
guzzlehttp/guzzle
Version ^6.2
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform