Package Health

nrel/nrel_solarpaces_profile

The stable version format and Composer build setup are clear, but the package has had no release or commit activity for years and lacks a security policy. Choose an actively maintained alternative rather than adding this abandoned dependency.

Latest 3.0.3.4PackagistPackagist

12%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

30

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.

Release historydanger

The latest release was published in April 2018, and there have been no releases in over eight years. The 39-release history shows prior activity but does not offset the prolonged silence.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with its archived status and indicating no current maintenance capacity.

Repository archiveddanger

The linked repository is archived and was last pushed in July 2020, so it is no longer an actively maintained source.

Repo toolingcaution

Composer is used for the build, which supports reproducible package management, but no security-scanning tooling was detected. This is a minor transparency and maintenance gap alongside the stronger abandonment signals.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Drew Michael

Direct Dependencies

DependencyLast ReleaseScore
drupal/redirect
Version ^1.0@beta
drupal/node_clone
Version 1.x-dev
drupal/paragraphs
Version ^1.1
nrel/communications
Version 3.0.4.1
drupal/config_update
Version ^1.5

Weekly Downloads

Info

Last Published
8 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform