Package Health

pepperlabs/pepper

The package has a clear MIT license, a readable README, repository tests, and release notes for this version. Its workflow has no detected dangerous sinks, but its unpinned actions and missing security scanning weaken maintenance hygiene. Do not adopt it without a maintained replacement.

Latest 2.2.2PackagistPackagist

18%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

58

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning that the release is no longer a supported dependency.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months. This supports the abandonment concern shown by the archived repository.

Repository archiveddanger

The linked repository is archived and was last pushed about four years ago, indicating the source is no longer actively maintained.

Release historycaution

The package has 24 releases but none in the last 12 months; its latest release was in January 2021. The earlier rapid release cadence does not compensate for the prolonged inactivity.

Repo issue activitycaution

The repository has 10 open issues, with no issues or pull requests opened or closed in the last month. This suggests unresolved maintenance demand without current activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Amirmasoud Sheydaei

Direct Dependencies

DependencyLast ReleaseScore
opis/closure
Version ^3.5
doctrine/dbal
Version ^3.0
tymon/jwt-auth
Version ^1.0
illuminate/support
Version ^8.0
rebing/graphql-laravel
Version ^6.1

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform