Package Health

maxfrerichs/t3-prometheus-client

This release appears generally suitable to depend on: it is not deprecated or archived, has a recent release, a meaningful release history, repository-backed documentation and tests, an explicit license, security policy, and no install-time lifecycle scripts or dangerous workflow patterns. The main concerns are that the project remains below a stable major version, all recent commits come from one maintainer, repository activity is modest, and the CI workflow does not declare top-level token permissions or use security-scanning tooling. These are manageable maintenance and transparency risks rather than evidence that the package is unfit for use.

Latest 0.11.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. Because project backing identifies an individual user rather than an organization, this creates a genuine continuity risk, though repository activity shows that the maintainer is currently active.

Project backingcaution

The linked repository is owned by a User rather than an organization, so there is no organizational backing to offset the single-maintainer concentration.

Repo bus factorcaution

All 4 recent commits came from one contributor, giving the project a complete single-contributor concentration and increasing continuity risk; the individual ownership context provides no organizational handoff evidence.

Repo issue activitycaution

There are 4 open issues and no issue or pull-request activity in the last month. The absence of recent resolution activity is a modest maintenance concern, but it is not by itself evidence of abandonment.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a hygiene gap, although other repository security signals are favorable.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Max Frerichs

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^13.4 || ^14.3
—
—
typo3/cms-scheduler
Version ^13.4 || ^14.3
—
—
promphp/prometheus_client_php
Version ^2.14
—
—
promphp/prometheus_push_gateway_php
Version ^1.1
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform