Package Health

murdej/latte-static-generator

The package offers little consumer documentation and limited project safeguards. Its recent release and active repository state provide some reassurance, but the licensing inconsistency should be resolved before adoption.

Latest v1.0.3PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The artifact declares GPL-2.0-only but its LICENSE file was detected as GPL-3.0; although both the artifact and repository contain license files, this mismatch creates a real licensing concern.

Package scaffoldingcaution

The package includes a changelog and the repository has one, but no README or tests were found. Missing tests are normal for published artifacts, while the missing README is a consumer-facing documentation gap for a static-generation tool.

Release historycaution

Only four releases have appeared since June 2022, with a median interval of about 19 months and one release in the last 12 months. The latest release is current, which partly offsets the sparse cadence.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, indicating limited ongoing development. The repository was pushed very recently for the assessed release, which provides partial compensation but not evidence of sustained activity.

Repo toolingcaution

Composer is used for builds, but no security-scanning tooling was found. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Vit Peprnicek

Direct Dependencies

DependencyLast ReleaseScore
nette/neon
Version ^3.3
—
—
latte/latte
Version ^3.0
—
—
nette/utils
Version ^3.2 || ^4.0
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform