Package Health

jdr/event-recorder-bundle

The README, changelog, repository tests, and MIT licensing provide useful documentation and transparency. Its single release and absent recent repository activity leave maintenance and compatibility uncertain for a new dependency.

Latest 0.0.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

This package has only one release, 0.0.1, published more than eight years ago, with no releases in the last twelve months. That strongly raises abandonment and compatibility risk.

Repo commit activitydanger

There were no commits or active maintainers in the last three months, consistent with the repository's last push being in December 2017. This is substantial evidence of inactivity.

Maintainerscaution

Only one registry account has publishing access. That can be normal for a small user-owned project, but it leaves limited visible publishing redundancy when there is no recent activity.

Project backingcaution

The repository is owned by an individual rather than an organization, and no broader organizational backing is shown. Combined with the lack of recent activity, this provides limited maintenance assurance.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these counters provide little supporting evidence of community adoption.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Johan de Ruijter

Direct Dependencies

DependencyLast ReleaseScore
jdr/event-recorder
Version ^0.0.2
—
—
jdr/event-recorder-doctrine-bridge
Version ^0.0.1
—
—
jdr/event-recorder-tactician-bridge
Version ^0.0.1
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform