Package Health

legionlab/restapi

The README, matching repository, and lack of install scripts provide useful transparency. However, releases and repository activity stopped in December 2016, while the project has no security scanning and only a nonstandard license declaration without a license file.

Latest 0.22PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package is over 9 years old but has only two releases, both published within minutes on December 18, 2016, and none in the last 12 months. This is strong evidence of abandonment risk.

Repo commit activitydanger

There were no commits and no active maintainers in the last 3 months, consistent with the release history showing no releases for years. This materially increases abandonment risk.

Licensecaution

The manifest declares “MITS,” but no license file was found in the package or repository and the detected license is null. The release therefore has weaker licensing transparency than the declaration alone suggests.

Repo toolingcaution

Composer is used for builds, but no security scanning tooling is present. For a PHP application framework, that is a meaningful maintenance and transparency gap, though it is not conclusive by itself.

Security policycaution

The repository has no security policy. This limits transparency about vulnerability reporting and response, adding to the concerns raised by the long period of inactivity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Vilarinho

Direct Dependencies

DependencyLast ReleaseScore
legionlab/rest-kernel
Version ^0.22
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform