Package Health

nattreid/reference-service

Its MIT license and focused seven-file artifact reduce transparency concerns. The lack of a security policy and security scanning leaves little evidence of ongoing stewardship.

Latest 1.2.2PackagistPackagist

42%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The latest release was in December 2017, with no releases in the last 12 months after 16 total releases. This long publishing gap is a substantial abandonment concern.

Repo package mentioncaution

The repository name matches the package, reducing the risk of a mismatched source repository, but the README does not mention the package explicitly. This is a minor transparency gap.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are configured. For a small package this is not decisive alone, but it provides little supply-chain assurance alongside the stale project activity.

Repository archivedcaution

The repository is not archived, which preserves a basic maintenance path, but it was last pushed in October 2018. The prolonged absence of source updates lowers confidence in continued support.

Security policycaution

No security policy is present in the linked repository, leaving no documented process for reporting or handling vulnerabilities.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Attreid

Direct Dependencies

DependencyLast ReleaseScore
nette/di
Version ~2.4
nattreid/utils
Version ~1.0
nette/reflection
Version ~2.4
nette/application
Version ~2.4

Weekly Downloads

Info

Last Published
8 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform