Package Health

jarir/nemesis-framework

This release appears suitable to depend on from a maintenance and transparency perspective: it is a stable major release with 24 releases in the last 12 months, active repository work including 31 commits from two contributors in the last three months, a non-archived source repository, a documented MIT license, repository tests, a changelog, and a security policy. The main concerns are the very small repository footprint in terms of popularity, concentration of 87.1% of recent commits in one contributor, 26 runtime dependencies, absence of automated security-scanning tooling, and an install-time post-create-project-cmd script. These warrant review and operational caution, but do not indicate abandonment or an otherwise unfit dependency.

Latest v7.1.4PackagistPackagist

79%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package declares 26 runtime dependencies and no dev dependencies, creating a relatively broad runtime supply-chain and compatibility surface. This is a meaningful review concern, despite the README describing the framework as zero-dependency.

Lifecycle scriptscaution

The post-create-project-cmd install-time script adds execution behavior during project creation and should be reviewed before adoption, although the signal does not establish that the script is unsafe.

Project backingcaution

The source repository is owned by an individual user rather than an organization, so the concentrated contributor pattern is not offset by visible organization-level maintenance backing.

Repo bus factorcaution

Recent work is concentrated at 87.1% in one contributor, which creates continuity risk. A second contributor is active with 4 of 31 commits, partially reducing but not eliminating the concentration concern.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is ambiguous—possibly reflecting a small or quiet project—so it provides little evidence of community support rather than a severe maintenance failure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jarir Ahmed

Direct Dependencies

DependencyLast ReleaseScore
aws/aws-sdk-php
Version ^3.372.0
—
—
jarir-ahmed/file
Version ^1.0
—
—
league/flysystem
Version ^3.31
—
—
jarir-ahmed/cache
Version ^1.0
—
—
jarir-ahmed/search
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform