Package Health

orchid/fortify

The repository has no recent commit or issue activity, and the workflow audit found a high-confidence unpinned container image. The MIT license, release notes, matching repository, and security policy provide useful transparency, but the long inactivity makes this a risky dependency.

Latest 0.0.12PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historydanger

The package has had no release in over three years: its latest release was May 28, 2023, despite 12 releases overall. This strongly raises abandonment risk, although the earlier median interval of about 44 days shows it was previously maintained.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months. Combined with the release history, this is strong evidence of prolonged abandonment risk.

Repo issue activitycaution

There are five open issues but no new or closed issues and no pull-request activity in the last month. This supports the view that maintenance is currently inactive.

Repo toolingcaution

The project uses Composer, but no security-scanning tooling was detected. That is a modest transparency and maintenance gap rather than evidence that the package is unsafe by itself.

Version stabilitycaution

Version 0.0.12 is not on a stable major version, so its API maturity is limited. It is not marked as a prerelease, which partly offsets the concern but does not remove the immaturity signal.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexandr Chernyaev

Direct Dependencies

DependencyLast ReleaseScore
laravel/fortify
Version ^1.16
orchid/platform
Version ^14.0

Weekly Downloads

Info

Last Published
3 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform