Package Health

hollisho/yii2-redis-pub-sub

The README and matching repository help with basic integration. There is little evidence of ongoing support or independent adoption, while the project lacks security scanning and a security policy.

Latest 0.1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historydanger

This is the package's only release, published nearly eight years ago, with no releases in the last 12 months. That provides strong evidence of abandonment risk, although the package is not marked deprecated.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in November 2018. This materially increases maintenance and abandonment risk.

Maintainerscaution

The registry has one publisher account, which limits visible publishing capacity for a small user-owned project. The matching repository owner provides some continuity but not evidence of active support.

Repo popularitycaution

The repository has only 1 star, 1 fork, and 1 watcher, so there is little external usage or review evidence to compensate for its lack of activity. Low popularity alone is not decisive for a small package.

Repo toolingcaution

Composer is used for the build, which is appropriate, but no security scanning tools are present. That is a transparency and maintenance gap for a package handling Redis-connected application code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Hollis Ho

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform