Package Health

irooit/wechat

It has a clear MIT license, a usable README, release notes, repository tests, and a substantial source tree. Install and update hooks, missing security scanning, and unpinned workflow actions add hygiene concerns.

Latest 5.5.1PackagistPackagist

56%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has 221 releases but none in the last 12 months, and its latest release was about five and a half years ago. This strongly lowers confidence in ongoing maintenance, although the long release history shows prior maturity.

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These increase install-time behavior and review burden, but the signal alone does not show that the scripts are unsafe.

Project backingcaution

The repository is owned by an individual user rather than an organization. This does not prove poor stewardship, but it offers less visible institutional backing for a project with no recent activity.

Repo issue activitycaution

There were no new or merged pull requests in the last month and no issue activity was recorded. Combined with the old last release, this supports a maintenance concern, while the null open-issue count limits what can be concluded.

Repo popularitycaution

The repository reports zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no visible community backing for a package with no recent releases.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

irooit

Direct Dependencies

DependencyLast ReleaseScore
pimple/pimple
Version ^3.0
symfony/cache
Version ^3.3 || ^4.3 || ^5.0
monolog/monolog
Version ^1.22 || ^2.0
psr/simple-cache
Version ^1.0
guzzlehttp/guzzle
Version ^6.2 || ^7.0

Weekly Downloads

Info

Last Published
5 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform