Package Health

openlss/lib-config

The small dependency set, included tests, README, and matching source repository make the package easy to inspect. Its license mismatch needs clarification, while the long period without maintenance makes future compatibility and support uncertain.

Latest 0.0.15PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Licensecaution

The manifest declares LGPL-3.0+, but the artifact license file was detected as GPL-3.0. Both the artifact and repository contain license files, but the mismatch should be resolved before adoption.

Release historycaution

The latest release was in September 2013, with no releases in the last 12 months. Roughly 13 years without a release is strong evidence of abandonment risk, despite the package having 15 releases overall.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance capacity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. For this small, long-inactive project, the missing scanning is a minor hygiene gap rather than the main concern.

Security policycaution

The repository has no security policy. This reduces vulnerability-reporting transparency, though the package's prolonged inactivity is the more significant concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Bryan Tong
Tony Butler

Direct Dependencies

DependencyLast ReleaseScore
openlss/func-mda
Version dev-master
—
—

Weekly Downloads

Info

Last Published
13 years ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform