Package Health

leanphp/symfony-api-skeleton

The MIT license, README, and matching organization-owned repository provide clear provenance and basic consumer guidance. Its broad dependency set has no visible security scanning or policy, and the project offers little ongoing support for a new API skeleton. Pinning this release would leave maintenance and compatibility risks with the adopter.

Latest v0.1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

This package has only one release, published over 8 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency intended for current projects.

Repo commit activitydanger

The repository has recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no updates since April 2018. The unarchived status does not compensate for the lack of observed activity.

Repo issue activitycaution

There is one open issue and no new or closed issues or pull requests in the last month. This is supporting evidence of inactivity, though the small project size limits how much can be inferred from issue volume alone.

Security policycaution

The linked repository has no security policy. For an API project with 17 runtime dependencies, this reduces transparency around vulnerability reporting and response.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/lts
Version ^4@dev
symfony/flex
Version ^1.0
symfony/yaml
Version ^4.0
symfony/console
Version ^4.0
symfony/orm-pack
Version ^1.0

Weekly Downloads

Info

Last Published
8 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform