Package Health

mortenscheel/tracer

Clear documentation, tests, and release notes make the package easy to evaluate. Its single-maintainer ownership and minimal adoption leave little evidence of ongoing support.

Latest 0.2.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Release historydanger

The package has only two releases, both published in March 2025, with no release in roughly 18 months. This weakens evidence of ongoing maintenance for a young package.

Repo commit activitydanger

There have been zero commits and zero active maintainers in the last three months, consistent with no repository activity since March 2025. This is the strongest maintenance concern in the assessment.

Lifecycle scriptscaution

A post-create-project-cmd Composer lifecycle script runs during project creation. This is worth noting because it adds install-time behavior, but the signal does not show that it is harmful or unusually broad.

Maintainerscaution

Only one registry account can publish the package. That creates a limited publishing base, although the linked repository is owned by the same individual and the short registry list is consistent with personal ownership.

Project backingcaution

The registry namespace and repository belong to the same individual account rather than an organization. This is consistent ownership, but it provides limited evidence of institutional backing.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Morten Scheel

Direct Dependencies

DependencyLast ReleaseScore
illuminate/collections
Version ^11|^12
mortenscheel/editor-links
Version ^0.2.0

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform