Package Health

mateodioev/tgbot

It has a clear README, a stable release line, and a long release history. The install hook and absent security policy add smaller transparency concerns.

Latest v4.8.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

The manifest declares MIT, but the bundled LICENSE file was detected as GPL-2.0. This unresolved mismatch creates a real adoption and compliance concern despite the presence of a license file.

Lifecycle scriptscaution

The package runs a post-install-cmd script, which adds install-time behavior that consumers must trust and inspect. No provided signal shows that this hook is necessary or harmless.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last 3 months, despite four registry releases in the last year. This suggests maintenance may be release-driven or currently paused.

Security policycaution

The repository has no security policy, and repo tooling reports no security scanning tools. This weakens vulnerability-reporting and maintenance transparency, though it is not evidence of a vulnerability.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
amphp/amp
Version ^3.0
—
—
amphp/file
Version ^3.0
—
—
mateodioev/utils
Version ^1.1
—
—
vlucas/phpdotenv
Version ^5.4
—
—
amphp/byte-stream
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform