Package Health

jelix/jelix-standard

This release is usable but warrants caution. The package has a long history since 2019, 47 releases including 14 in the last 12 months, a stable non-prerelease version, no registry deprecation, an explicit LGPL-2.1-or-later license, organization backing, and no install-time scripts. However, the linked repository is unusually minimal, with only three files and no tests or changelog, shows no commits or active maintainers in the last three months, has no security policy or security-scanning tooling, and has negligible repository adoption. Recent registry releases provide evidence of ongoing publishing, but the lack of visible development activity and project hygiene reduces confidence in long-term maintenance and transparency.

Latest v1.8.27PackagistPackagist

63%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package file treecaution

The artifact and repository each contain only .gitignore, README.md, and composer.json. This may be appropriate for a Composer distribution wrapper, but it provides little source or validation context for the release.

Package scaffoldingcaution

A useful README explains that this is a standard-component distribution and documents installation, but both the artifact and repository lack tests and a changelog, leaving maintenance and release transparency less well supported.

Repo commit activitycaution

The repository reports zero commits and zero active maintainers in the last three months. Recent package releases partly compensate for this gap, but the absent source-development activity remains a meaningful maintenance concern.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently unhealthy, but combined with the minimal repository it offers little evidence of active community maintenance.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little external evidence of community adoption or review.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Laurent Jouanneau
Jelix Community

Direct Dependencies

DependencyLast ReleaseScore
jelix/jelix
Version 1.8.27
jelix/feeds-module
Version ~1.7.6
jelix/wikirenderer-plugin
Version ~1.7.4

Weekly Downloads

Info

Last Published
14 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform