Package Health

odwini/tag

Risky to depend on: the package has had no release in about seven years and its artifact contains only a manifest and license, with no README. It is not deprecated and has modest dependencies, but the lack of repository transparency and extremely limited package contents make adoption a liability.

Latest 1.0.1PackagistPackagist

38%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

0

Health Score Breakdown

Package file treedanger

The published artifact contains only LICENSE.md and composer.json, leaving no implementation files or usage documentation visible. This unusually thin package contents create a substantial transparency and usability concern.

Release historydanger

The latest release was about seven years ago, with only two releases overall and none in the last 12 months. This is strong evidence of abandonment risk, despite the package reaching a stable 1.0.1 version.

Package scaffoldingcaution

The package has no README, while tests and a changelog are normally expected in the source repository rather than the published artifact. The missing README still reduces consumer transparency for a package intended to provide CMS functionality.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nicolas Widart

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ~1.0

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform