Package Health

ourren/yii2-ssh2

The source offers little verification, with no tests, a very short README, and no security policy. MIT licensing and a matching repository make the package transparent, but they do not offset the maintenance concern.

Latest 0.1.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has had only two releases, both in May 2016, and none in the last 12 months. This long period without a release is strong evidence of abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of recent releases. The repository is not archived, but there is no observed recent maintenance.

Package scaffoldingcaution

The artifact includes a README, but it is only 23 characters long, and the source repository has no tests or changelog. Missing tests and changelogs are not packaging defects by themselves, but the minimal documentation weakens consumer transparency.

Repo toolingcaution

Composer is used for the build, which supports reproducible package management, but no security scanning tool is present. This is a hygiene gap rather than evidence that the release is unsafe.

Security policycaution

The linked repository has no security policy. This is a modest transparency and vulnerability-reporting gap, especially for a library handling SSH connections.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

ourren

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version *
—
—
phpseclib/phpseclib
Version 2.0.*
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform