Package Health

macocci7/php-histogram

Clear documentation, tests, and regular releases support adoption. Recent commit activity is absent, and the lone maintainer plus unpinned workflow actions leave some maintenance and build-reproducibility concerns.

Latest 2.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Dependency profilecaution

Five runtime dependencies create moderate dependency surface for a library, including related project packages and required PHP extensions; this is a manageable but nontrivial maintenance burden.

Maintainerscaution

Only one registry maintainer is listed. The matching user-owned repository shows direct ownership, but the narrow publishing base still increases continuity risk.

Repo commit activitycaution

No commits and no active maintainers were recorded during the last three months. This is partly offset by a release about five months ago, but it still indicates a current maintenance gap.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanner is a hygiene gap rather than evidence of unsafe code.

Security policycaution

The repository has no security policy. That reduces vulnerability-reporting transparency, although it does not by itself show abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

macocci7

Direct Dependencies

DependencyLast ReleaseScore
nette/neon
Version ^3.4
—
—
fakerphp/faker
Version ^1.24
—
—
macocci7/php-plotter2d
Version ^1.0
—
—
macocci7/php-frequency-table
Version ^1.4
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform