Package Health

phifty/cartbundle

Latest 3.1.0PackagistPackagist

32%

Total Score

unhealthy

Risky: no release or commit activity since July 2016, with only two releases and no security policy.

Health Score Breakdown

Licensedanger

The manifest declares a proprietary license, with no detected license text or license file in the package or repository. This leaves important usage terms unclear for an open-source dependency.

Release historydanger

The package has only two releases, both dating from June 2016, and none in the past 12 months. That long release gap is strong evidence of abandonment risk.

Repo commit activitydanger

There were zero commits and zero active maintainers in the past three months. Combined with the repository's last push in 2016, this indicates no observed current maintenance.

Project backingcaution

The repository owner is an organization, and the registry namespace aligns with that ownership. This provides some backing context, but no recent activity shows that the organization still maintains the package.

Repo popularitycaution

The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but this provides little community signal to compensate for the lack of recent maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

c9s

Direct Dependencies

DependencyLast ReleaseScore
corneltek/esunacq
Version ^1.0
—
—
composer/installers
Version ~1.0.0
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform