Package Health

lucite/utils

The package has tests, a declared MIT license, and only two runtime dependencies. Its repository does not clearly identify the package, and the project lacks a security policy, reducing transparency for a library dependency.

Latest 0.0.6PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The six releases were concentrated in September 2024, with no release in roughly two years and none in the last 12 months. This indicates a release history that has stopped rather than an actively maintained package.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months, consistent with the repository having received no updates since September 2024. This materially raises abandonment risk.

Repo package mentioncaution

The repository name does not match lucite/utils, and no README package mention was available. The repository may not clearly belong to this package, which weakens provenance transparency.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. This is supporting evidence of limited adoption and project visibility, though popularity alone does not determine health.

Repo toolingcaution

Composer is used for the build, but no security scanning tool is configured. The missing scanning is a modest transparency and maintenance gap, not evidence of a defect by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mike Thorn

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
psr/http-message
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform