Package Health

loantap/finvu

The stable release, explicit GPL-3.0-or-later license, and lack of install-time scripts reduce adoption friction. The tiny artifact and missing security process leave limited transparency for a library.

Latest 1.0.1PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

Only two releases were published, both in August 2022, with none in the last four years. This is strong evidence of abandonment risk for a package intended for API integration.

Repo commit activitydanger

The repository had no commits and no active maintainers in the last three months, consistent with the long gap since its last push. This materially increases the risk that defects and compatibility issues will remain unaddressed.

Package file treecaution

The artifact and repository each contain only three files: .DS_Store, composer.json, and finvu.php. That may be enough for a very small wrapper, but it provides little visible documentation, testing, or project structure for an API library.

Package scaffoldingcaution

The release includes GitHub release notes stating that a variable name changed, which documents this version. However, it has no README, tests, or changelog, leaving consumers with little integration guidance or visible validation.

Repo toolingcaution

Composer is used as the build tool, but no security-scanning tooling is present. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Loantap

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^4.2
—
—
composer/installers
Version ~1.0
—
—
oomphinc/composer-installers-extender
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform