Package Health

imedge/web-select2

The project has a clear MIT license, tests, organization backing, and only one runtime dependency. Its release cadence is slow, recent commit activity is absent, and all six workflow actions are unpinned; no security policy is published.

Latest v0.6.0PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

Only two releases span about 23 months, with one release in the last 12 months and a median interval of about 18 months. This indicates a slow maintenance cadence, though the package was released recently enough that abandonment is not established.

Repo commit activitycaution

There were zero commits and zero active maintainers during the last three months. Combined with the long release interval, this leaves current maintenance capacity uncertain.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The build setup is established, while security automation remains a transparency gap.

Security policycaution

The repository has no published security policy. This weakens vulnerability-reporting transparency, although it is not by itself evidence that the package is unsafe.

Version stabilitycaution

Version v0.6.0 is not a stable major release, which suggests the public API may still change. It is not marked as a prerelease, so this is a moderate rather than severe concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Thomas Gelf

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform