Package Health

johnatas-x/angry-bearded

This is an actively maintained and stable package with a strong release cadence, recent repository activity, a non-archived matching source repository, and no registry deprecation. However, dependency adoption carries meaningful hygiene and resilience concerns: the package has no detected license, no tests or changelog, all recent commits come from one contributor, the repository lacks a security policy and security scanning, and its workflow grants top-level write permissions. The package is usable, but these gaps make it a moderate-risk dependency rather than a fully mature, well-governed one.

Latest 3.10.7PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 24 runtime dependencies, most of which are development and static-analysis tools. This is a broad dependency surface for a tooling bundle and increases maintenance and transitive-dependency exposure.

Licensecaution

No declared license or license file was detected in the artifact or repository. This creates a real transparency and legal-adoption concern for downstream developers.

Maintainerscaution

Only one registry account has publish access. Because the repository is user-owned rather than organization-owned, the narrow publishing base provides limited continuity if that maintainer becomes unavailable.

Package scaffoldingcaution

A substantial README is present, but neither the artifact nor repository contains tests or a changelog. For a configuration/tooling package, missing tests are a maintenance gap, while the missing changelog reduces release transparency.

Project backingcaution

The source repository is owned by the user account johnatas-x, not an organization. The active owner provides evidence of current backing, but there is no organizational handoff capacity shown.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Johnatas

Direct Dependencies

DependencyLast ReleaseScore
drupal/coder
Version 9.0.1
phpro/grumphp
Version 2.23.0
povils/phpmnd
Version 3.6.1
phpstan/phpstan
Version 2.2.13
johnatas-x/phpcpd
Version 6.0.5

Weekly Downloads

Info

Last Published
11 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform