Package Health

kode/miniapp

This release appears usable and actively developed, with a stable non-prerelease version, no registry deprecation, a linked non-archived repository, substantial documentation, tests, changelog coverage, and a clear Apache-2.0 license declaration. The main concerns are concentrated maintenance ownership—87 commits in the last 3 months all came from one contributor—and the absence of repository security scanning and a security policy; the unusually rapid release cadence also warrants some operational scrutiny. Overall, it is a viable dependency, but teams should monitor maintainer continuity and review the release process before relying on it for critical integrations.

Latest 2.0.42PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Project backingcaution

The repository owner is an individual GitHub user rather than an organization, so the single-contributor concentration is not compensated by visible organization-level maintenance backing.

Release historycaution

The package is only 138 days old but has 100 releases, including releases within the collection window; this demonstrates active publishing, although a median interval of about 34 minutes is unusually rapid and merits release-process scrutiny.

Repo bus factorcaution

One contributor made all 87 commits in the last 3 months, creating a fragile bus factor and making the project more exposed to maintainer absence or handoff failure.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but this provides little external validation for a package intended for broad platform integration.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The build setup is adequate while security-process transparency is limited.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kode Lab

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
kode/pays
Version ^2.0
—
—
symfony/cache
Version ^6.4|^7.0
—
—
monolog/monolog
Version ^3.5
—
—
psr/simple-cache
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform