Package Health

jbboehr/yumemi-apocrypha

This is a young but actively developed development-tooling package with clear licensing, documentation, changelog, source repository alignment, repository tests, and substantial recent commit activity. Its main risks are the short 22-day history, provisional 0.x API, complete dependence on one contributor, absent security-scanning tooling and security policy, and minimal adoption evidence; these make it usable with monitoring rather than a highly mature dependency. The repository is not archived or deprecated, has no install-time lifecycle scripts, and its workflow risk profile is clean, which provides meaningful reassurance.

Latest v0.3.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. This is a genuine publishing continuity concern for an individually owned project, although repository activity shows that the maintainer is currently active.

Project backingcaution

The repository owner is an individual user rather than an organization, so there is no demonstrated organizational handoff or backing to offset the single-maintainer concentration.

Release historycaution

The package is only 22 days old with three releases and a median interval of about 11 days, providing evidence of active early development but little long-term maintenance history.

Repo bus factorcaution

All 98 recent commits come from one contributor, creating a high bus-factor risk. The owner is actively contributing, but no second active maintainer is shown to provide continuity.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently negative for a package only 22 days old, but it provides little evidence of external review or maintenance collaboration.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

John Boehr

Direct Dependencies

DependencyLast ReleaseScore
jbboehr/yumemi
Version ^0.2
—
—
phpstan/phpstan
Version ^2.2.5
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform