Package Health

nih/app-skeleton

The package has a detailed README, repository tests, and clear MIT licensing. Its early-stage 0.x status and limited security tooling leave less evidence for long-term support.

Latest 0.1.2PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Project backingcaution

The package is linked to the matching nih-soft repository, but the repository owner is an individual account rather than an organization. This gives some ownership context without strong organizational backing.

Release historycaution

The package has only three releases, all published within roughly one day, followed by about 5 months without another release. That short launch burst provides limited evidence of sustained maintenance.

Repo commit activitycaution

The repository has recorded zero commits and zero active maintainers in the last 3 months. Combined with the short release history, this is meaningful evidence that development has gone quiet.

Repo popularitycaution

The repository has 3 stars, no forks, and no watchers, indicating a very small user and contributor footprint. Popularity is only supporting evidence, but this offers little external evidence of maturity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe dependency risk on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
nih/router
Version ^0.2.0
nih/container
Version ^0.1.3
nih/http-kernel
Version ^0.1.3
psr/http-factory
Version ^1.1

Weekly Downloads

Info

Last Published
5 months ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform