Package Health

kfosoft/yii2-app-dynamic-options

The repository has had no commits for over five years, and the project has no security scanning or security policy. It is not archived, has an accurate repository link, a useful README, and organization backing, which provide some transparency.

Latest 21.02PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published over five years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a package intended as a maintained application component.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing prolonged inactivity. The linked repository is not archived, but that does not offset the absence of recent work.

Repo popularitycaution

The repository has 0 stars, 1 fork, and 1 watcher. Low popularity is only supporting evidence, but it leaves little external adoption signal to compensate for the prolonged inactivity.

Repo toolingcaution

Composer is used for builds, which is appropriate for this package, but no security scanning tools are configured. That is a maintenance and transparency gap, though not severe on its own.

Security policycaution

The repository has no security policy. This weakens vulnerability-reporting transparency, especially for a package that handles application configuration and database-backed options.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kyrylo Checherskyi

Direct Dependencies

DependencyLast ReleaseScore
kfosoft/php-int-enum-x64
Version 20.11
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform