Package Health

nigatedev/yaml

Risky to adopt: this package has had no release or commit activity for about five years and has almost no project maturity evidence beyond a minimal five-file artifact. It may be usable for a narrow need, but ongoing maintenance and support should not be expected.

Latest v1.0.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has only two releases, both published about five years ago, with no releases in the last 12 months. This is strong evidence of an inactive project.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring about five years ago. The lack of recent maintenance materially increases abandonment risk.

Package file treecaution

The release contains only five files: a parser, manifest, README, license, and gitignore. This is transparent and simple, but it provides little evidence of mature development or validation.

Package scaffoldingcaution

The package includes a README and has a GitHub release for this version, but neither the artifact nor repository has tests or a changelog. Those omissions are not inherently wrong for a small compiled or library artifact, though they leave limited evidence of quality.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no additional confidence in a project that is otherwise inactive.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Abass Ben Cheik

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version v5.3.6
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform