Package Health

mnapoli/bref

Regular releases and active repository work provide useful continuity. The organization-backed project has tests, release notes, a security policy, and a matching source repository, but the registry status should be resolved before adopting.

Latest 3.0.12PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, which is a serious adoption warning; the listed replacement is the same package, while active release and repository signals partly contradict the status.

Repo bus factorcaution

One contributor made about 96% of recent commits, creating a substantial concentration risk; organization backing provides some handoff capacity but does not remove the concern.

Repo toolingcaution

The project uses Make and Composer, but no security-scanning tools were detected; this is a modest transparency and assurance gap rather than evidence of abandonment.

Workflow auditcaution

All three workflows were analyzed with no high- or medium-confidence findings involving untrusted input. All 17 action references are unpinned, and two workflows install packages outside a lockfile, leaving reproducibility and workflow hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
nyholm/psr7
Version ^1.4.1
—
—
psr/container
Version ^1.0|^2.0
—
—
symfony/process
Version ^5.4|^6.4|^7.0|^8.0
—
—
psr/http-message
Version ^1.0|^2.0
—
—
crwlr/query-string
Version ^1.0.3
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform