Package Health

hexmakina/black-box

Usable with caveats: the package is licensed, not deprecated or archived, and still had a recent release and repository push. However, it has no tests, no security policy, no recent commit activity, and the linked repository does not identify or mention this package.

Latest 0.1.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Maintainerscaution

One registry maintainer account is listed. The repository is owned by the same individual rather than an organization, so the narrow publishing base provides limited redundancy.

Package scaffoldingcaution

The artifact and repository contain a short README but no tests or changelog. GitHub Releases provide some release documentation, but the lack of tests still reduces maintainability transparency for a reusable interface package.

Project backingcaution

The registry namespace and repository owner match, but the owner is an individual account rather than an organization, offering less visible institutional backing.

Release historycaution

The package has existed for about 5 years with 8 releases and one release in the last 12 months, showing it is not abandoned, though the release history is sparse.

Repo commit activitycaution

There were zero commits and zero active maintainers during the last 3 months. The recent repository push and registry release show some activity, but current development capacity appears limited.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

HexMakina

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version 1.1.*
—
—

Weekly Downloads

Info

Last Published
14 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform