Package Health

phpcq/plugin-deptrac

This is a generally healthy package to depend on: it has a stable 1.1.0 release, an active non-archived organization-owned repository, recent commit and pull-request activity, tests, Composer-based build tooling, Dependabot scanning, and no install-time lifecycle scripts. The main concerns are a sparse release history, only one active contributor in the last three months, very low repository popularity, and missing security-policy and top-level workflow permission declarations. These warrant monitoring and review of maintenance continuity, but do not currently indicate abandonment or an unfit dependency.

Latest 1.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historycaution

The package is about 4 years and 8 months old but has only 3 releases, with a median interval of about 849 days and only 1 release in the last 12 months. This indicates slow release cadence and some maintenance uncertainty, despite the recent release.

Repo bus factorcaution

All 6 commits in the last 3 months came from one contributor, producing a complete concentration of recent activity. This is a meaningful continuity risk, although organization ownership may allow maintenance to be handed off.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 2 watchers. Low popularity is not disqualifying for a niche plugin, but it provides little external evidence of broad community adoption.

Security policycaution

No security policy is present in the repository, reducing transparency about vulnerability reporting and coordinated disclosure.

Token permissionscaution

The only workflow lacks top-level token permissions declarations. No write permissions were observed, but explicit least-privilege declarations would provide stronger assurance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christian Schiffler
David Molineus

Direct Dependencies

DependencyLast ReleaseScore
phpcq/plugin-api
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform