Package Health

neonxp/dotenv

There is no repository security policy or security scanning, although the README, tests, and MIT license are present. Its simple dependency profile and lack of install scripts reduce exposure but do not offset the maintenance risk.

Latest 0.0.1PackagistPackagist

38%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has only one release, 0.0.1, published about 8 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these counts provide little evidence of an active user or contributor community.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance concern.

Security policycaution

The repository has no security policy. For a library that parses environment files, this weakens the project's documented security reporting and maintenance posture.

Version stabilitycaution

The latest version is 0.0.1 and is not a stable major release, leaving maturity uncertain; the absence of later releases reinforces that concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexander Kiryukhin

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
8 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform