Package Health

lidev/hello-world

This is a very small, clearly scoped Composer package with an MIT license, a complete four-file artifact, minimal runtime dependencies, no install-time lifecycle scripts, and no registry deprecation. The linked repository is organization-owned, matches the package context through its README, and is not archived. However, the release is brand new with only one release and no observed commit or issue activity beyond initial publication; it also has no tests, changelog, security policy, or security scanning. Those gaps are partly understandable for a minimal Hello World example, but the package has little demonstrated maintenance history, so it is usable but should not yet be treated as a mature dependency.

Latest v1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Package scaffoldingcaution

A README is present and explains installation and usage, but neither the artifact nor repository contains tests or a changelog. For a minimal Hello World library this is a modest hygiene gap rather than a severe risk.

Release historycaution

Only one release exists and the package age is 0 days, so there is no historical evidence of sustained maintenance or release reliability.

Repo commit activitycaution

There were zero commits and zero active maintainers in the preceding three months. Because the package is newly released, this primarily reflects limited evidence of ongoing maintenance, but it still lowers confidence in its maturity.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are present. The simple package structure limits the significance of this omission, though it leaves less automated security hygiene.

Security policycaution

The repository has no security policy. This is a transparency gap, although the package's minimal scope and absence of observed workflows reduce the immediate operational concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
22 days ago
Created
22 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform