Package Health

onetoweb/mendrix-tms

The small, clearly scoped package has a usable README, changelog, matching source repository, and limited dependencies. Its MIT license and organization backing help, but the maintenance and security coverage remain thin.

Latest v1.0.3PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has made no release in nearly three years: its latest release was October 26, 2023, with no releases in the last 12 months. This is strong evidence of abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the absence of current maintenance activity.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month. With no recent commits, this indicates a project that is currently inactive rather than actively stable.

Repo popularitycaution

The repository has zero stars and forks and only two watchers. Popularity is not required for health, but these figures provide no supporting evidence of broad adoption or review.

Repo toolingcaution

Composer is used for builds, which is appropriate, but no security scanning tools are present. That leaves limited visible evidence of automated security checks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jonathan van 't Ende

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^1.40|^2.9|^3.0
guzzlehttp/guzzle
Version ^6.0 || ^7.0

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform