Package Health

loremipsumdev/hello-world

This is a clean, very small Composer package with an MIT license, a complete minimal file tree, no install-time lifecycle scripts, no deprecation notice, and organization-backed repository ownership. However, it is newly published with only one release and no observed commit activity, tests, changelog, security policy, or security-scanning tooling. Those gaps are less concerning for a minimal Hello World library than they would be for a complex package, but the release has little demonstrated maintenance history, so adoption warrants normal verification and monitoring.

Latest v1.0.0PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

A README is present, but neither the artifact nor repository contains tests or a changelog. For a minimal example package this is understandable, though it leaves limited evidence of validation and release transparency.

Release historycaution

Only one release exists and the package is 0 days old, so there is no demonstrated release or maintenance track record yet.

Repo commit activitycaution

There were zero commits and zero active maintainers in the measured three-month window. Because the package is newly created, this mainly indicates insufficient maintenance history rather than confirmed abandonment, but it lowers confidence in ongoing support.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is weak supporting evidence, but the package is newly published and popularity is not decisive for a tiny library.

Repo toolingcaution

Composer is used as the build tool, but no security-scanning tooling is present. The lack of scanning is a hygiene gap, although the package is unusually small and has no complex build process.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
22 days ago
Created
22 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform