Package Health

lion/framework

This release appears suitable for dependency use: it is a stable, non-deprecated release from a package with a consistent release history, current repository activity, matching source repository, tests, changelog, licensing, and security tooling. The main concerns are that all four commits in the last three months came from one contributor, the repository has very low adoption indicators, no security policy was found, and the workflow does not declare top-level token permissions. These merit monitoring and review of the install script, but do not outweigh the evidence of active maintenance and organizational backing.

Latest v5.1.9PackagistPackagist

80%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

An install-time post-root-package-install script runs during installation, which adds execution surface and warrants review, although the signal does not establish that the script is unsafe.

Repo bus factorcaution

One contributor made 100% of the four recent commits, creating a concentrated maintenance dependency; the organization-owned repository provides some backing but does not eliminate the observed single-contributor risk.

Repo commit activitycaution

The repository recorded four commits in the last three months, showing recent activity, but all activity came from only one active maintainer.

Repo popularitycaution

The repository has only 4 stars, 0 forks, and 0 watchers, indicating limited adoption and external validation; this is a supporting concern rather than evidence of abandonment.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting expectations less transparent; the repository's separate security scanning tools partly compensate for this gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
lion/bundle
Version ^19.2
—
—
lion/mailer
Version ^8.0
—
—
symfony/mailer
Version ^8.0
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform