Package Health

ju1ius/macaron

The repository is organized, tested, licensed, and clearly matches the package. Its maintenance and publishing evidence is too old for a new dependency, and the registry marks the package abandoned; pinning this release carries substantial risk.

Latest 0.6PackagistPackagist

29%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Registry deprecationdanger

The registry marks the entire package as abandoned, with no replacement beyond the same package name. This is a severe warning for continued dependency support.

Release historydanger

Only five releases have been published, and none appeared in the last 12 months; the latest release was over two years ago. The early release cadence does not compensate for the prolonged publishing gap.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This materially raises abandonment risk.

Security policycaution

The repository has no security policy. For a cookie-handling library this reduces transparency about vulnerability reporting, though the clean workflow audit and existing tests provide some compensation.

Workflow auditcaution

The workflow audit completed cleanly with no dangerous triggers, untrusted checkouts, injection findings, or audit failures. However, all 4 analyzed action references are unpinned, leaving a supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

ju1ius

Direct Dependencies

DependencyLast ReleaseScore
psr/clock
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—
souplette/fusbup
Version ^1.0
—
—
psr/clock-implementation
Version *
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform