Package Health

limingxinleo/swoft-project

Its Apache-2.0 license, included tests, and clear package structure support transparency. The broad 30-package runtime dependency set and absent security tooling add maintenance overhead.

Latest 1.4.7PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was published in January 2019, with no releases in the last 12 months despite the package being about 8 years old. This is strong evidence of abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and leaving current maintenance capacity unproven.

Dependency profilecaution

The release declares 30 runtime dependencies, including many framework components and extensions. That broad dependency surface increases compatibility and maintenance risk for an already inactive release.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, with one issue still open; this provides no evidence of active project response.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. This is a modest supply-chain transparency gap, especially for a package with many runtime dependencies.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
swoft/db
Version ~1.1
—
—
swoft/rpc
Version ~1.0
—
—
swoft/i18n
Version ~1.0
—
—
swoft/task
Version ~1.0
—
—
swoft/view
Version ~1.0
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform