Package Health

lampace/core

The source is only three files and lacks security scanning, limiting transparency and maintenance evidence. Organization backing and a non-archived repository offer little practical reassurance after the long silence.

Latest 0.0.1PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

This package has made only one release, 0.0.1, first published about 5 years and 4 months ago, with no releases in the last 12 months. That strongly suggests abandonment rather than an actively maintained dependency.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last 3 months, consistent with the absence of registry releases since May 2021. This leaves little evidence of ongoing maintenance.

Licensecaution

The manifest declares BSD-3-Clause, but the artifact license file was detected as GPL-3.0. Although a license file is present, the mismatch creates a material legal and transparency concern for consumers.

Package file treecaution

The package and repository each contain only three files: .gitignore, LICENSE, and composer.json. This extremely minimal source provides little implementation, usage, or maintenance transparency.

Package scaffoldingcaution

The published artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README reduces guidance for consumers of this library.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform