Package Health

jolalau/think6-captcha

The package has a clear license, a usable README, and no install-time scripts. Its single-maintainer, untested project has no security policy, so pinning this old release carries substantial maintenance risk.

Latest 1.0.4PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

70

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published in August 2021, and there have been no releases in the last 12 months despite the package being about five years old. This is strong evidence of abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months, consistent with the release history showing no recent maintenance.

Maintainerscaution

Only one registry publishing account is listed. That is a limited support base for a user-owned project and increases continuity risk when combined with the absence of recent activity.

Repo popularitycaution

The repository has 0 stars, 0 forks, and 1 watcher, providing little evidence of community review or support. Popularity is supporting evidence, so this reinforces rather than determines the maintenance concern.

Security policycaution

No security policy is present in the repository, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though it is less severe than the lack of recent development.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

jolalau

Direct Dependencies

DependencyLast ReleaseScore
topthink/framework
Version ^6.0.0
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform