Package Health

lexide/syringe

Healthy and reasonable to depend on, with strong project history, clear licensing, tests, and a current stable release. Recent repository activity is quiet and the project lacks security tooling, so review maintenance periodically.

Latest 3.0.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, which is a maintenance concern for a dependency. However, the package has a release in the last year and the repository was recently pushed, so this is caution rather than abandonment evidence.

Repo issue activitycaution

The repository has six open issues but no issues or pull requests were opened, closed, or merged in the last month. That indicates limited visible issue-tracking activity and modestly reduces confidence in responsiveness.

Repo popularitycaution

The repository has no stars and only one fork, indicating a small user and contributor footprint. Popularity is supporting evidence rather than a verdict, and the long release history and organization backing compensate for the limited adoption signals.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool is configured. This is a transparency and process gap, though it is not by itself evidence that the package is unsafe or abandoned.

Security policycaution

The repository has no published security policy. That makes vulnerability-reporting expectations less clear, but it is a moderate hygiene gap rather than a severe dependency risk given the package's release history and tests.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0.1 || ^2.0 || ^3.0
symfony/yaml
Version ^6.0.0 | ^7.0.0 | ^8.0.0
pimple/pimple
Version ^3.0.0

Weekly Downloads

Info

Last Published
6 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform