Package Health

jplhomer/blade-library

It has had no release since July 2020 and no recent commits, although the README, tests, license, and static analysis provide useful project context. Pinning a different maintained package would be safer.

Latest v0.0.2PackagistPackagist

8%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on the release.

Release historydanger

Only two releases exist, both from July 2020, and there have been no releases in the last 12 months. This strongly supports the abandonment concern despite the package having an identifiable release history.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months. Combined with its archived status, this shows no current maintenance capacity.

Repository archiveddanger

The linked repository is archived and was last pushed in January 2022, indicating the source is no longer maintained. The repository does match the package and mentions it, so this is not a linkage concern but remains a severe abandonment risk.

Workflow auditcaution

All eight analyzed action references are unpinned, and a high-confidence audit found an unpinned container image. This is a workflow hygiene weakness, though it is secondary to the package's abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Josh Larson

Direct Dependencies

DependencyLast ReleaseScore
livewire/livewire
Version ^1.2
—
—
illuminate/filesystem
Version ^7.18
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform