Package Health

phpmv/ubiquity-project

The template includes a README, release notes for this version, and a clear create-project workflow. Its single maintainer, minimal repository, absent security policy, and lack of security scanning leave limited evidence of ongoing project support.

Latest 1.0.9PackagistPackagist

46%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. The repository is organization-owned, so a short registry maintainer list is not inherently concerning, but it still provides limited evidence of release resilience.

Release historycaution

The latest release was published in June 2021, with no releases in the following 12 months and no newer release observed by the assessment date. This is a substantial abandonment concern despite a previously regular release interval.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no recent maintenance capacity.

Repo popularitycaution

The repository has 1 star, 0 forks, and 1 watcher. Low popularity is only supporting evidence, but it provides little external sign of adoption or community support.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tools were detected. The missing scanning is a modest supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jean-Christophe HERON

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.0
phpmv/ubiquity
Version ^2.3

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform