Package Health

mztest/yii2-single-file-upload

The extension is small and clearly tied to its source repository, with a README covering installation and usage. Its stable release and lack of deprecation help, but the maintenance evidence is too old for a dependable current dependency.

Latest 1.0.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

There has been only one release, published over 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, despite the package not being formally deprecated.

Project backingcaution

The registry namespace and repository owner match, and the owner is an individual account rather than an organization. This provides direct ownership alignment but no broader project backing.

Repo commit activitycaution

The repository had zero commits and zero active maintainers during the last 3 months, consistent with the long period since its last push. This materially increases maintenance and abandonment risk.

Repo popularitycaution

The repository has zero stars, forks, and watchers, providing no supporting evidence of adoption or an active user community. Popularity is only supporting evidence, so this reinforces rather than creates the maintenance concern.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling is present. This is a modest transparency and hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

mztest

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version >=2.0.7
blueimp/jquery-file-upload
Version *

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform