Package Health

mgcosta/mysql-to-cloud-spanner

Clear documentation, tests, release notes, and licensing make the project easier to evaluate and maintain locally. Its last release and repository push were in November 2021, with no recent commits, while all three workflow actions are unpinned.

Latest v0.4.4PackagistPackagist

54%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These add installation-time behavior that consumers should understand, although this signal alone does not show that the scripts are unsafe.

Maintainerscaution

One registry maintainer is consistent with a small, user-owned project, but it provides little redundancy if that maintainer stops supporting the package.

Release historycaution

The package has 25 releases, but its latest release was in November 2021 and it has had no releases in the last 12 months. The long period without a release is a meaningful maintenance concern.

Repo commit activitycaution

There were no commits or active maintainers in the last three months, and the repository was last pushed in November 2021. The repository is not archived, but the prolonged inactivity raises abandonment risk.

Security policycaution

The repository has no security policy, leaving consumers without a documented reporting path. This is a transparency gap, though it is less severe than the maintenance inactivity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Miguel Costa

Direct Dependencies

DependencyLast ReleaseScore
google/cloud-spanner
Version ^1.44.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform