Package Health

humanmade/meta-lookups

The six-file package is easy to inspect and has concise usage documentation. Organization backing and release notes help, but long-term maintenance evidence is absent; verify the GPL terms before adoption.

Latest v1.1PackagistPackagist

44%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

Only two releases were published, both in March 2019, with no release in more than seven years. This is strong evidence of abandonment for a package developers may need to maintain over time.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being more than seven years ago. No provided maintenance signal compensates for this inactivity.

Licensecaution

The manifest declares GPL-2.0-or-later, while the artifact license file was detected as GPL-3.0. Although a license file exists, the mismatch creates avoidable uncertainty about the terms governing this release.

Repo popularitycaution

The repository has 4 stars and 1 fork, indicating a small user and contributor footprint. Low popularity is only supporting evidence, but it compounds the limited maintenance signal.

Repo toolingcaution

Composer is used for the build, which supports reproducible package structure, but no security-scanning tooling was found. This is a modest transparency and hygiene gap rather than evidence of an unsafe release.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ^1

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform