Package Health

luwc/webman-yii2-orm

The package has a substantial README, repository tests, and a source repository that clearly matches its name. Install and update hooks add some operational risk, while the absent security policy leaves limited guidance for reporting issues.

Latest v1.0.1PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts, adding installation-time behavior that consumers must account for. No provided signal shows those hooks are unsafe, so this is a limited hygiene concern rather than a severe risk.

Project backingcaution

The registry namespace is a user account and the source repository is owned by a different user account, so there is no demonstrated organizational backing. The matching repository and package mention provide some compensation, making this a mild concern rather than a severe ownership problem.

Release historycaution

This is a 395-day-old package with only one release and no releases in the last 12 months, which raises maintenance and abandonment concerns. The linked repository is still present and unarchived, but that does not demonstrate ongoing release activity.

Repo popularitycaution

The repository has zero stars, forks, and watchers, so there is little visible community adoption or review. Popularity is supporting evidence only, and the package's small scope means this does not by itself make it unfit.

Repo toolingcaution

Composer is used as the build tool, which fits the PHP package ecosystem, but no security scanning tools were detected. The missing scanning tooling modestly reduces transparency for a database and validation library.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

luwc

Direct Dependencies

DependencyLast ReleaseScore
illuminate/database
Version ^8.0|^9.0|^10.0
—
—
illuminate/pagination
Version ^8.0|^9.0|^10.0
—
—
illuminate/validation
Version ^8.0|^9.0|^10.0
—
—
workerman/webman-framework
Version ^2.1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform