Package Health

kabachello/codiware

Codiware 0.9 appears reasonably healthy to depend on: it is actively released, not deprecated or archived, has a matching repository with a clear README, MIT licensing, substantial source and documentation, and recent activity from two contributors with balanced commit shares. The package is still young and pre-1.0, has no tests, no security policy or security scanning, and uses a moderately broad runtime dependency set, so it carries meaningful maturity and maintenance-process risk. Overall, it is usable but should be adopted with normal safeguards and awareness that its API may still evolve.

Latest 0.9PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package declares 12 runtime dependencies, including several frontend asset packages and Symfony/Guzzle components. This is a notable dependency-surface consideration, but the profile is understandable for the package's web IDE functionality rather than inherently excessive.

Package scaffoldingcaution

A substantial README and changelog are present, and repository releases compensate for the absence of packaged and repository tests. The lack of tests remains a modest maturity gap for a web IDE with file, Git, and console functionality.

Project backingcaution

The repository is owned by the individual user kabachello rather than an organization. This is valid project backing but leaves less organizational maintenance redundancy than an organization-owned project.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 0 watchers. This is weak supporting evidence and limits external validation, but popularity alone does not establish poor health for a young package.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. The missing security automation lowers process maturity without indicating abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1 || ^2.0 || ^3.0
guzzlehttp/psr7
Version ^2.0
symfony/process
Version ^5.4 || ^6.4 || ^7.0
psr/http-factory
Version ^1.0
psr/http-message
Version ^1.1 || ^2.0

Weekly Downloads

Info

Last Published
10 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform