Package Health

metrixs/mx-cookieless-analytics

Usable with caveats: the release is active, licensed, documented, and not deprecated, but it is only 11 days old and all recent repository work comes from one contributor. The missing security policy and lack of security scanning add transparency concerns for a package that handles analytics integration.

Latest 1.1.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Project backingcaution

The registry namespace is metrixs, but the linked repository is owned by an individual account rather than an organization. This provides limited organizational continuity evidence.

Release historycaution

The package is very young at 11 days old, with three releases and a median interval of about 6 days. This shows active initial development but provides little evidence of long-term maintenance.

Repo bus factorcaution

One contributor made all six commits in the last three months, leaving maintenance dependent on a single individual and increasing abandonment or handoff risk.

Repo popularitycaution

The repository has no stars, forks, or watchers. Given that the package is only 11 days old, this is weak supporting evidence rather than a standalone adoption concern.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a transparency gap, though it does not by itself show that the release is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

MetriXs Analytics

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^5.0.0
—
—

Weekly Downloads

Info

Last Published
12 days ago
Created
23 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform