Package Health

overtrue/yaf-skeleton

The package includes a README, tests, a stable version, and a matching source repository. Its registry listing is deprecated, the repository is archived, and no releases or commits have appeared for more than eight years, making this a poor foundation for new projects.

Latest 1.1.1PackagistPackagist

10%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on the package.

Release historydanger

The package has only three releases, all ending in July 2018, and none in the last 12 months. More than eight years without a release indicates severe abandonment risk despite the earlier regular cadence.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months. Together with its archived state, this provides no evidence of ongoing maintenance.

Repository archiveddanger

The linked source repository is archived, which indicates the project is no longer actively maintained. Its last push was more than four years ago, with no newer maintenance evidence provided.

Repo toolingcaution

Composer is used as the build tool, showing basic project tooling, but no security scanning tools are configured. This is a minor hygiene gap that does not outweigh the abandonment evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

overtrue

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^1.0
monolog/monolog
Version ~1.0
symfony/console
Version 3.*
psr/http-message
Version ~1.0

Weekly Downloads

Info

Last Published
8 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform