Package Health

karelwintersky/arris

This is a mature, actively maintained Composer package with a release history dating back to 2019, 103 releases, 17 releases in the last 12 months, and 49 recent repository commits. The repository is active, unarchived, correctly associated with the package, and backed by an organization, while the artifact has clear documentation, a declared MIT license, no install-time scripts, and repository tests. The main concerns are that all recent commits come from one contributor, the repository has very low adoption metrics, no security policy or security-scanning tooling, and the package has a relatively broad runtime dependency and PHP-extension footprint. Overall it appears usable for dependency adoption, but its limited maintainer redundancy and security-process maturity warrant monitoring.

Latest 2.203.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package declares 10 runtime dependencies, including several PHP extensions and another Arris package; this is a meaningful integration footprint, though it is not inherently unhealthy for a framework core.

Maintainerscaution

Only one registry account has publish access. This is partly compensated by the ArrisFramework organization backing the repository, but publishing continuity still depends on a narrow registry access base.

Repo bus factorcaution

One contributor made all 49 commits in the last three months, creating a clear bus-factor and continuity risk. Organization ownership provides some potential handoff capacity but does not show a second active contributor.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these values provide little external validation or redundancy.

Repo toolingcaution

The repository uses Make and Composer for build-related tasks, which supports reproducibility, but it has no detected security-scanning tooling.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Karel Wintersky

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version *
—
—
karelwintersky/arris.config
Version ^1
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform