Package Health

kearth/tea

The linked repository and package name align, and the artifact has a README and declared license. The release is nearly six years old, remains prerelease, has no commits in the past three months, and its PHP artifact differs sharply from the repository's Go-oriented tree; the license mismatch adds uncertainty.

Latest v1.0.0-alphaPackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

58

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package file treedanger

The published artifact is a small PHP framework tree, while the linked repository tree is predominantly Go with Go modules and source files. This weakens confidence that the repository fully explains how this release was built.

Release historydanger

This is the package's only release, published nearly six years ago, with no releases in the past 12 months. That leaves the assessed version materially stale for a dependency.

Licensecaution

The manifest declares Apache-2.0, but the repository license file is detected as MIT. Although both provide licensing, the mismatch creates avoidable provenance and usage uncertainty.

Repo commit activitycaution

The repository shows zero commits and zero active maintainers in the past three months. A recent push exists, but the lack of current commit activity still points to uncertain ongoing maintenance.

Repo issue activitycaution

There are five open pull requests but no new or closed issues or merged pull requests in the past month. This suggests visible activity without demonstrated review or release follow-through.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

kearth

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform