Package Health

muna/framework

The small runtime dependency surface and declared MIT license make adoption straightforward. Limited documentation, no recent repository activity, and weak workflow and security hygiene reduce confidence in ongoing maintenance.

Latest v1.0.26PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package scaffoldingcaution

The artifact has no README, but absent tests and changelog files are normal for published artifacts and are not concerns by themselves. The missing README is a modest documentation gap for a framework library.

Release historycaution

The package published 26 releases in a concentrated period of about one week, but there is no release activity after April 13, 2026; this suggests momentum may have stalled.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months, leaving little evidence of sustained maintenance after the initial release burst.

Repo package mentioncaution

The repository name does not match the package name, and the README could not be checked for a package mention. This creates some uncertainty about whether the linked repository is the package's direct source.

Repo toolingcaution

Composer is used for the build, but no security scanning tooling is present, reducing automated visibility into dependency or source issues.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform