Package Health

jupitern/slimcore

This release is usable but presents meaningful maintenance and transparency concerns. The package has a clear MIT license, stable releases, 16 releases over 480 days, recent publication activity, no deprecation, and no install-time lifecycle scripts. However, the linked personal repository has no commits or active maintainers in the last 3 months, no tests or changelog, no security scanning or security policy, and negligible adoption signals. The repository was pushed very recently and the release cadence is steady, which partially offsets the inactivity concern, but the thin project infrastructure and single-person backing make this a dependency to adopt with caution.

Latest 4.4.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health checks

Dependency profilecaution

The package has five runtime dependencies and no dev dependencies. The dependency set is moderate, but the absence of dev dependencies also aligns with the absence of repository tests and reduces evidence of development validation.

Package scaffoldingcaution

The artifact and repository contain only a very short README and no tests or changelog; the repository's GitHub Releases provide some release transparency but do not compensate for the lack of validation and documentation.

Project backingcaution

The repository is owned by a user rather than an organization, indicating a relatively thin backing model. This matters more given the lack of recent commits and external popularity signals.

Repo commit activitycaution

The repository records 0 commits and 0 active maintainers in the last 3 months, a material maintenance concern. The very recent repository push and steady release history partly offset this, so the signal is caution rather than danger.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently negative for a small package, but it provides no evidence of an active user or contributor feedback loop.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
slim/psr7
Version 1.8.*
slim/slim
Version 4.15.*
monolog/monolog
Version 2.* || 3.*
vlucas/phpdotenv
Version 5.7.*

Weekly Downloads

Info

Last Published
10 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform