Package Health

palacios/framework

This is a very young, pre-1.0 package with only two releases over 2 days, so its long-term maintenance, API stability, and operational maturity are not yet established. The linked repository is active, correctly associated with the package, unarchived, and includes substantial documentation, tests, a changelog, a license, security policy, CI workflow, and read-only workflow permissions. However, all 10 recent commits come from one contributor, the repository has no observed popularity or issue activity yet, and no security-scanning tooling is reported. It is usable for experimentation or closely monitored adoption, but should be treated as a higher-change-risk dependency rather than a mature production foundation.

Latest v0.1.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Project backingcaution

The repository is owned by the user account Palacyos rather than an organization, so there is no organizational backing to offset the concentrated contributor base.

Release historycaution

The package is only 2 days old and has 2 releases, so there is too little history to demonstrate sustained maintenance or mature release practices. The roughly 2-day median release interval shows early activity but not durability.

Repo bus factorcaution

One contributor made all 10 recent commits, producing a 100% top-contributor share and a significant continuity risk for a user-owned project.

Repo popularitycaution

The repository has 0 stars, forks, and watchers. For a package only 2 days old this is not evidence of abandonment, but it provides no external adoption or maturity support yet.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are reported. The missing scanning layer is a genuine transparency and maintenance gap for a framework, though it is not by itself evidence of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
17 days ago
Created
19 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform