Package Health

phpmob/chang

The package is correctly linked to its source and has clear MIT licensing. Its tiny README, absent security policy, and minimal project activity leave substantial maintenance risk.

Latest v4.1.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

Only two releases were published, with none in the last seven years and none in the past 12 months. This strongly suggests the package is no longer actively maintained.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.

Package scaffoldingcaution

A GitHub release note documents this version, but the package README contains only eight characters and the repository has no tests or changelog. The release note partly compensates for missing changelog material, not the inadequate consumer documentation.

Repo popularitycaution

The repository has one star and no forks, providing little evidence of a broad user or contributor base. Popularity is supporting evidence, but this reinforces the maintenance concerns.

Repo toolingcaution

Composer build tooling is present, which supports a recognizable build process, but no security-scanning tooling is configured and the project has no recent activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ishmael Doss

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^3.7
—
—
twig/extensions
Version ^1.5
—
—
fzaninotto/faker
Version ^1.7
—
—
sylius/grid-bundle
Version ^1.2
—
—
sylius/user-bundle
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform