Package Health

laeawa/bephp-composer-hello

The package is small and stable, with only PHP as a runtime dependency and no install-time scripts. Its MIT license is present in the artifact, and this version has release notes, but adoption carries meaningful abandonment risk.

Latest 2.0.0PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has only 2 releases, both from October 2022, with no release in roughly four years. This strongly indicates an inactive project, although a small stable library may not need frequent releases.

Repo commit activitydanger

The repository had 0 commits and 0 active maintainers in the last 3 months, consistent with a project that has been inactive for roughly four years.

Repo package mentioncaution

The repository name does not match the package name, and no README package mention was observed. This creates some uncertainty that the linked repository is the package's primary project, though a subpackage or educational repository can explain a mismatch.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 1 watcher. Popularity is not required for a healthy small package, but these values provide no supporting evidence of active use or community resilience.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency gap rather than a standalone reason to reject a small package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

LaeAwa

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform