Package Health

model/skeleton

The repository clearly matches the package and is backed by an organization, which gives the small project useful ownership context. Its create-project installer and README fit the package's template role.

Latest v0.1.4PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

58

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensedanger

The manifest declares the package proprietary, with no detected license and no license file. That creates a material legal and transparency concern for a package intended to be used as an open-source dependency.

Release historycaution

All five releases appeared within roughly 6 minutes on the first release day, and there has been no later release during the package's 137-day lifetime. This suggests an immature release history rather than an established maintenance cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months, despite being only 137 days old. That is a meaningful maintenance and abandonment concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and supply-chain hygiene gap, not evidence that the package is unsafe.

Security policycaution

The repository has no security policy. For a small, newly released project this reduces clarity about vulnerability reporting and response expectations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Domenico Giambra

Direct Dependencies

DependencyLast ReleaseScore
model/core
Version ^0.4
—
—
model/assets
Version ^0.4
—
—
model/router
Version ^0.2
—
—
model/settings
Version ^0.2
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform