Package Health

leuchtdiode/mezzio-common

This release appears usable and transparently packaged, with an MIT license, source repository, tests and changelog, stable versioning, no deprecation, no install-time lifecycle scripts, and frequent recent releases. However, the linked repository shows no commits or active maintainers in the last 3 months, has no security scanning or security policy, and has no observable community activity; combined with a single registry maintainer and zero stars or forks, this creates meaningful maintenance and sustainability risk. The package is not currently unfit to depend on, but its continued health should be verified before adopting it for a long-lived or security-sensitive project.

Latest 2.0.10PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo commit activitydanger

The repository records 0 commits and 0 active maintainers in the last 3 months, indicating collapsed or absent source-development activity. This materially offsets the frequent registry releases and is the strongest maintenance concern in the assessment.

Dependency profilecaution

The package declares 17 runtime dependencies and only 1 development dependency, creating a relatively broad transitive dependency surface that raises maintenance exposure compared with a smaller package. The signal does not show that any dependency is unsafe, so this is a moderate caution rather than a severe risk.

Maintainerscaution

Only one account, Alex Schloegl, has registry publish access. This is a limited publishing redundancy signal, and the repository owner is also a user rather than an organization; actual repository activity is therefore especially important to continued support.

Project backingcaution

The repository is owned by the user account leuchtdiode rather than an organization, so there is no organizational backing signal to compensate for the single registry maintainer or absent recent commits.

Repo issue activitycaution

There are no open issues or pull requests and no new or closed issue or pull-request activity in the last month. While a clean issue tracker can be benign, the complete absence of activity offers no evidence of an engaged support community.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alex Schloegl

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version ^3.13.0
—
—
symfony/cache
Version ^8.1.0
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—
laminas/laminas-i18n
Version ^2.33.0
—
—
laminas/laminas-view
Version ^2.44.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform