Package Health

pkostadinov-2create/carbon-field-number

The package is small and clearly identified, with straightforward contents and stable metadata. Its maintenance and release history are effectively dormant, while documentation, testing, and security tooling are minimal. Pin this version only if its narrow functionality is sufficient and you can maintain it locally.

Latest v1.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

Only one release exists, published about 10 years ago, with no releases in the last 12 months. This is strong evidence of a dormant package and raises abandonment risk.

Repo commit activitydanger

There were no commits and no active maintainers in the last 3 months. Combined with the single historical release, this indicates sustained inactivity rather than a short pause.

Package scaffoldingcaution

A README is present and the release has a GitHub release, but the README is only 22 characters and the package and repository contain no tests or changelog. The GitHub release partly documents the release process, but consumer guidance remains minimal.

Project backingcaution

The repository is owned by an individual account rather than an organization, providing no organizational backing to compensate for the package's thin maintenance record.

Repo toolingcaution

The repository uses no build tooling and has no security scanning. For a small PHP extension this is not inherently disqualifying, but it leaves little evidence of modern project safeguards.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Plamen Kostadinov

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform