Package Health

oneago/arcturus-core

The license conflict makes redistribution and compliance unclear. A missing security policy and absent repository security tooling add transparency concerns, while the repository remains linked and unarchived.

Latest v5.1.1PackagistPackagist

39%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has 33 releases but none in the last four years; its latest release was in September 2022, which is a substantial abandonment risk despite its earlier release history.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long registry pause and leaving no evidence of current maintenance.

Licensecaution

The manifest declares MIT, but the artifact license file is detected as GPL-3.0; although license files exist in both the artifact and repository, the mismatch creates a real compliance concern.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, providing little evidence of external review or community support. Low popularity is supporting caution rather than a verdict by itself.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. That leaves dependency and code issues less likely to be detected, though it is not evidence of malicious behavior.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

jruedaq
jyarar
Oneago

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.4
—
—
symfony/console
Version ^v6.1
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform