Package Health

ixocreate/media-package

Its MIT licensing, README, changelog, tests, and organization-backed repository provide useful transparency. The small user base and lack of security scanning add modest maintenance concerns.

Latest 0.5.4PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has 37 releases, but none in the last 12 months and the latest release was in July 2021, about five years ago. This is strong evidence of stale maintenance for a dependency still being considered.

Repo commit activitydanger

The repository had no commits and no active maintainers in the last three months, consistent with the long release gap. This materially increases abandonment risk.

Repo popularitycaution

The repository has one star, zero forks, and two watchers, indicating very limited external adoption or review. Popularity is supporting evidence rather than decisive on its own, but it adds a modest maturity concern.

Repo toolingcaution

Composer is used for the build, but no security-scanning tools were detected. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.

Security policycaution

The repository has no security policy. This weakens the documented response path for vulnerabilities, although the README provides an email contact for reporting them.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

IXOCREATE

Direct Dependencies

DependencyLast ReleaseScore
cocur/slugify
Version ^4.0
—
—
symfony/asset
Version ^5.2
—
—
firebase/php-jwt
Version ^5.0
—
—
intervention/image
Version ^2.4.1
—
—
ixocreate/collection
Version ^0.2
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform