Package Health

neuron-php/cli

This release appears suitable for dependency use, with strong evidence of active maintenance and reasonable package maturity: it has 21 releases over roughly 13 months, 16 releases in the last 12 months, a very recent push, an MIT license, comprehensive README and test coverage, and a non-archived repository backed by an organization. The main reservations are that recent repository activity is entirely concentrated in one contributor, the repository has no security policy or security-scanning tooling, and its CI workflow does not declare top-level token permissions. These are meaningful transparency and continuity gaps, but they do not outweigh the package's active release cadence, tests, and organizational backing.

Latest 0.8.16PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a continuity concern, although registry access records do not establish actual maintenance capacity and the repository is organization-owned.

Repo bus factorcaution

All 3 recent commits came from one contributor, creating a genuine single-person continuity risk; organization ownership provides some compensating handoff capacity but does not remove the concentration.

Repo commit activitycaution

There were 3 commits in the last 3 months, with one active maintainer. The recent activity is present but relatively light and concentrated, warranting some maintenance caution.

Repo popularitycaution

The repository has no stars, forks, or watchers, so external adoption is not demonstrated; popularity is supporting evidence only and this does not outweigh the active releases and maintenance signals.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured. The missing scanning is a transparency gap, while build tooling is appropriate for the package ecosystem.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Lee Jones

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^6.4
neuron-php/data
Version 0.9.*
neuron-php/application
Version 0.8.*

Weekly Downloads

Info

Last Published
9 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform