Package Health

jawira/skeleton

jawira/skeleton appears to be a healthy, actively maintained release: it has existed since 2018, has 62 releases, published five releases in the last 12 months, and the current version is stable and not deprecated. The linked repository is active, unarchived, matches the package, and shows recent pull-request and commit activity, while the MIT license and build scaffolding are clear. The main concerns are that all recent commits come from one contributor, there are no repository tests or changelog, and no security scanning or security policy was observed; these are meaningful resilience and transparency gaps but do not outweigh the package's long release history and current activity.

Latest v2.33.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry publishing account is listed. This is a modest operational resilience concern, although repository activity shows that the publishing identity is currently active.

Package scaffoldingcaution

A README and build documentation are present, but neither the artifact nor repository contains tests or a changelog. For a reusable build/scaffolding package this reduces verification and change-history transparency, though the repository does include explicit PHPUnit tooling.

Project backingcaution

The repository is owned by a user account rather than an organization, so the concentrated ownership and contributor activity represent a real single-owner continuity risk.

Repo bus factorcaution

All seven recent commits came from a single contributor, creating a genuine continuity risk if that contributor becomes unavailable.

Repo toolingcaution

Composer and Phing build tooling are present, but no security scanning tools were detected. The build setup is positive, while the absent scanning is a modest security-hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jawira Portugal

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
18 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform