Package Health

josbeir/cakephp-synapse

The package is well documented and tested, with clear release notes and no install-time scripts. Its young 0.x status, single active contributor, missing security policy, and unpinned workflow actions leave meaningful maintenance and build-integrity concerns.

Latest 0.3.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Dependency profilecaution

Six runtime dependencies, including the actively evolving MCP SDK, create some update and compatibility exposure for a young integration plugin.

Project backingcaution

The repository is owned by an individual rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.

Repo bus factorcaution

One contributor made all two commits in the last three months, leaving maintenance concentrated entirely in a single person-owned project.

Repo commit activitycaution

Only two commits were recorded in the last three months, indicating limited recent development activity despite the strong release cadence.

Repo issue activitycaution

There are no open issues or pull requests, but there was also no issue or pull-request activity in the last month, so this is weak evidence of ongoing community maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
mcp/sdk
Version ^0.7
—
—
symfony/finder
Version ^7.0 || ^8.0
—
—
cakephp/cakephp
Version ^5.2
—
—
symfony/filesystem
Version ^7.0 || ^8.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform