Package Health

jungleran/composer-group

The package is extremely small, with no tests, changelog, README, or security policy to help consumers assess changes and support. Its single runtime dependency keeps integration simple, but the project offers little ongoing transparency.

Latest v0.0.4PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

57

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was published in June 2019, more than 7 years ago, and there have been no releases in the last 12 months. This is strong evidence of abandonment risk for a package still being adopted today.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. No newer activity is provided to compensate for this maintenance concern.

Licensecaution

Neither the package nor the linked repository declares or contains a recognized license file. That leaves the legal terms for reuse unclear.

Package scaffoldingcaution

The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. The GitHub release flag is positive, but its release notes are absent and does not compensate for the limited documentation and validation evidence.

Repo toolingcaution

Composer is used as a build tool, which is appropriate, but no security scanning tools are reported. This is a modest transparency gap rather than a severe defect.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jungle Ran

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform