Package Health

ibrand/wechat-backend

It has an MIT license, a usable README, and source that matches the package under organization ownership. Its eight runtime dependencies and lack of security scanning or a security policy add maintenance and oversight burden.

Latest v1.0.10PackagistPackagist

44%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published in October 2019, with no releases in the last 12 months. This is a substantial abandonment concern for a framework integration package.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last 3 months, reinforcing the long release gap and indicating no current maintenance activity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That leaves dependency and code-health checks less evident than they would be in a more actively maintained project.

Repository archivedcaution

The repository is not archived, which is a meaningful compensating signal, but its last push was in February 2022 and does not offset the prolonged lack of releases and recent commits.

Security policycaution

The repository has no security policy. This weakens vulnerability-reporting transparency, though it is an oversight gap rather than evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

shjchen

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ^2.7
overtrue/wechat
Version ~4.0
ibrand/laravel-active
Version ~2.0
prettus/l5-repository
Version ^2.1
laravelcollective/html
Version ^5.5

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform