Package Health

monad/skeleton

This is a healthy, actively developed release with strong artifact hygiene and unusually concrete project documentation: it is licensed, includes tests and a changelog, has a complete-looking 85-file application skeleton, and has received 12 stable releases in 43 days. The linked repository is organization-owned, not archived, was pushed recently, and shows substantial recent activity across three contributors with no severe contributor concentration. The main reservations are the package's short history, minimal external adoption, absence of repository security scanning and a security policy, and an install-time post-create script whose behavior should be reviewed before use. These concerns warrant normal dependency review but do not currently make the release unfit to depend on.

Latest v1.2.0PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

The package uses a post-create-project-cmd script, which adds install-time execution risk; its README documents that it generates the environment and application secret, providing some transparency but not eliminating the need to review the script.

Release historycaution

Twelve releases in 43 days, with a median interval of about 2.2 days, show active publishing, although the 43-day package age means long-term maintenance is not yet demonstrated.

Repo popularitycaution

The repository has only 1 star and no forks or watchers, indicating limited adoption; popularity is supporting evidence rather than a decisive health verdict, so this is a modest concern.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured, leaving a security-process gap even though this is not evidence of maliciousness.

Security policycaution

The repository has no SECURITY.md or equivalent policy, reducing vulnerability-reporting transparency and maintainer process visibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marshal Yung

Direct Dependencies

DependencyLast ReleaseScore
monad/clarity
Version ^1.0
vlucas/phpdotenv
Version ^5.6

Weekly Downloads

Info

Last Published
13 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform