Package Health

jbboehr/yumemi

This is a promising but very young pre-1.0 package with strong repository evidence of active development: 370 commits in the last three months, a current non-archived repository, extensive documentation and source scaffolding, a changelog, and repository tests despite tests not being included in the artifact. The main adoption risks are its 24-day history, v0.2 stability contract, single maintainer and sole contributor, zero observed popularity or issue activity, and lack of a security policy. It is not deprecated, has a clear AGPL license, uses read-only workflow permissions, and shows no analyzed dangerous workflow patterns, so it appears usable with normal caution around API stability and maintainer concentration.

Latest v0.2.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. This is a real continuity concern for a user-owned project, although repository activity shows that the maintainer is currently active.

Project backingcaution

The repository is owned by the individual user jbboehr rather than an organization, so there is no observed organizational backing to offset the single-maintainer and single-contributor risks.

Release historycaution

The package is only 24 days old with three releases and a median release interval of 12.4008 days (about 12 days), so there is not yet enough history to establish long-term maintenance reliability.

Repo bus factorcaution

All 370 recent commits came from one contributor, giving the project a complete contributor concentration and creating a significant continuity risk without organizational backing.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is ambiguous for a new package and is weaker evidence than a demonstrated maintenance backlog or resolution history.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

John Boehr

Direct Dependencies

DependencyLast ReleaseScore
doctrine/lexer
Version ^3.0
—
—
symfony/polyfill-php84
Version ^1.34
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform