Package Health

move/stack

This release is usable but carries meaningful transparency and maintenance concerns. The artifact is reasonably well structured, includes tests, has an MIT declaration, and uses no install-time lifecycle scripts, while the package is not deprecated. However, it has only two releases across roughly 15 months, remains below 1.0, is controlled by one registry maintainer, and has no declared source repository, limiting verification of ongoing maintenance, provenance, and contributor breadth. The package may be acceptable for a bounded use case, but it should be adopted with monitoring and without assuming strong long-term support.

Latest 0.9.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

80

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Dependency profilecaution

Eight runtime dependencies form a relatively broad dependency surface for a framework package, increasing upgrade and transitive-maintenance exposure. The profile is not inherently excessive, but it warrants more scrutiny given the limited release history.

Maintainerscaution

A single registry account has publish access, indicating a thin administrative bus factor. This is not evidence of actual inactivity by itself, but it increases continuity and release-control risk when repository activity is unavailable.

Release historycaution

Only two releases exist over approximately 15 months, with one release in the last 12 months and a median interval of about 466 days. This indicates limited demonstrated release activity and lowers confidence in sustained maintenance.

Version stabilitycaution

Version 0.9.1 is not a prerelease, but it is below the 1.0 major-stability threshold, so compatibility and maturity remain less established.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Martijn Heijnen

Direct Dependencies

DependencyLast ReleaseScore
filp/whoops
Version ~2.18.0
symfony/cache
Version ~8.0.0
symfony/mailer
Version ~8.0.0
monolog/monolog
Version ~3.10.0
symfony/console
Version ~8.0.0

Weekly Downloads

Info

Last Published
9 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform