Package Health

krisanalfa/scarf-kernel

It includes tests, a README, and no install-time scripts, but has one maintainer and no security policy. The repository is not archived, though its tooling shows no security scanning.

Latest 1.0.0PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historydanger

The package has only one release, published about 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk despite the package not being deprecated.

Maintainerscaution

Only one registry maintainer is listed, leaving limited visible publishing capacity and a high bus-factor concern. No organizational backing is shown to compensate for that thin registry maintainer base.

Repo toolingcaution

Composer and Phing provide build tooling, but no security-scanning tooling is reported. That is a modest hygiene gap rather than evidence that the release is unsafe.

Repository archivedcaution

The repository is not archived, which is positive, but it was last pushed about 10 years ago. The stale source activity materially weakens confidence in ongoing maintenance.

Security policycaution

The repository has no security policy. This is a transparency and response-process gap, although it is less serious than the long-standing lack of release activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Krisan Alfa Timur

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^5.2
monolog/monolog
Version ^1.17
illuminate/cache
Version ^5.2
nikic/fast-route
Version ^0.7.0
illuminate/config
Version ^5.2

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform