Package Health

meplato/store2

Usable with caveats: the package is licensed, tested, organization-backed, and not deprecated or archived. However, it has had no registry release in over two years and no commits in the last three months, so maintenance may be slowing.

Latest v2.1.13PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has 24 releases over more than 10 years with a typical release interval of about 47 days, but there have been no registry releases in the last 12 months and the latest release was over two years ago. This is a meaningful maintenance concern for a library dependency.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. The repository's push seven months ago provides some evidence of continued availability, but not of current maintenance.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting guidance unclear. This is a transparency gap, though it does not by itself make the package unfit to use.

Token permissionscaution

Neither analyzed workflow declares top-level token permissions. The absence of explicit least-privilege settings is a workflow hygiene concern, although no workflow was observed requesting top-level write access.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Meplato Developers

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ~7.5
guzzlehttp/uri-template
Version ^1.0

Weekly Downloads

Info

Last Published
2 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform