Package Health

morebec/orkestra-event-sourcing

It has clear documentation, tests, licensing, and an organization-backed repository. However, the release and repository have had no activity for more than three years, making future fixes and compatibility work uncertain.

Latest v2.5.6PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has 21 releases since April 2021, but none in the last 12 months and the latest release was over three years ago. This is strong evidence of stalled maintenance.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with the release history showing no release for over three years. This materially raises abandonment risk.

Repo popularitycaution

The repository has 1 star, 0 forks, and 1 watcher. Low popularity is supporting caution about external validation, but it does not by itself make a small maintained library unhealthy.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That weakens repository hygiene, though it is less serious than the prolonged inactivity.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a library used in application infrastructure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

jwillp

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^4.1
—
—
morebec/orkestra-enum
Version ^2.5.6
—
—
morebec/orkestra-worker
Version ^2.5.6
—
—
morebec/orkestra-datetime
Version ^2.5.6
—
—
morebec/orkestra-modeling
Version ^2.5.6
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform