Package Health

junjulini/plugin-project

Clear licensing, a changelog, and release notes make the package transparent to consumers. Its small dependency surface and organization backing help, but the repository has no recent development and lacks security policy or scanning. The repository matches the package, despite not naming it in the README.

Latest v1.1.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

Composer post-create and post-update scripts run during project creation or updates, adding execution surface for dependents. This is a mild supply-chain hygiene concern, not evidence of malicious behavior.

Release historycaution

The package has 12 releases over about five years, but none in the last 12 months; its latest release was in September 2024, indicating materially slowed maintenance.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, consistent with no registry releases in the last year and a significant maintenance slowdown.

Repo package mentioncaution

The repository name matches the package, so it does not appear to be piggy-backing on an unrelated project. The package name is absent from the README, which slightly weakens package-to-repository transparency.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. For a maintained open-source package, that leaves a modest transparency and maintenance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Junjulini

Direct Dependencies

DependencyLast ReleaseScore
junjulini/zimbrucode
Version ^1.3.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform