Package Health

layla/cody

Risky to adopt: the last release was over 12 years ago and the repository has had no commits in the last three months. It is not deprecated or archived, and it has a useful README, changelog, and organization backing, but the prolonged inactivity makes maintenance and compatibility a liability.

Latest 0.2.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

58

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has had only 3 releases, with the latest published over 12 years ago and none in the last 12 months. This is strong evidence of abandonment risk despite the short early release interval.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last three months, reinforcing the long gap since the latest release. No provided activity signal compensates for this lack of current maintenance.

Dependency profilecaution

The package declares 9 runtime dependencies, including framework, parser, and documentation-generation components. This is a moderately broad dependency surface for an old package and can increase compatibility maintenance costs when the project is inactive.

Package scaffoldingcaution

The package includes a substantial README and a changelog, while the absence of tests in the published artifact is normal packaging practice. Repository tests are also absent, leaving limited evidence of ongoing validation.

Repo toolingcaution

Composer is used as a build tool, providing basic project build structure, but no security scanning tools are configured. The tooling evidence is limited and does not compensate for the lack of recent development activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Koen Schmeets
Roj Vroemen

Direct Dependencies

DependencyLast ReleaseScore
sami/sami
Version dev-master
—
—
symfony/yaml
Version ~2.4
—
—
illuminate/view
Version ~4.2
—
—
nikic/php-parser
Version 0.9.*
—
—
illuminate/events
Version ~4.2
—
—

Weekly Downloads

Info

Last Published
12 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform