Package Health

kgolinski/turboenum

The package has a clear MIT license, tests in the repository, and minimal runtime dependencies. Its single release, no commits in the last three months, missing security policy, and workflow permission and pinning issues make long-term maintenance less certain.

Latest 1.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump install script adds execution during installation, creating some supply-chain exposure, though this is a limited and common Composer lifecycle hook rather than evidence of an unsafe package.

Project backingcaution

The package and repository are owned by the same individual account, so the source relationship is clear, but there is no organization backing to compensate for a single-owner project.

Release historycaution

This is the only release since the package launched about 10 months ago, so there is little release history from which to judge maturity or ongoing maintenance.

Repo commit activitycaution

No commits and no active maintainers were recorded during the last three months, which weakens evidence of current maintenance for a package with only one release.

Security policycaution

The repository has no security policy, leaving contributors and users without a documented reporting path; this is a transparency gap for a package intended for dependency use.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Krzysztof Goliński

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
10 months ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform