Package Health

jwcobb/tevo-harvester

The package includes a README, tests, release notes, a matching source repository, and a clear MIT license. Its install scripts and lack of a security policy add smaller maintenance and review concerns.

Latest 4.1.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has 26 releases since March 2016, but none in the last 12 months and its latest release was in June 2022, over four years ago. This is strong evidence of slowing maintenance.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months. Combined with the old latest release, this materially raises abandonment risk.

Lifecycle scriptscaution

The package runs post-autoload, post-create-project, post-install, and post-update scripts. These are plausible for a Composer-created Laravel application but increase install-time behavior that adopters must understand.

Repo issue activitycaution

There are no new or closed issues in the last month and no merged pull requests, with one pull request still open. This supports the conclusion that active maintenance is limited.

Repo popularitycaution

The repository has 1 star, 5 forks, and 3 watchers. This is limited supporting evidence, but popularity is not required for a small, clearly scoped application.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ^3.1
—
—
laravel/tinker
Version ^2.5
—
—
guzzlehttp/guzzle
Version ^7.0.1
—
—
laravel/framework
Version ^8.54
—
—
fruitcake/laravel-cors
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform