Package Health

pnx/doom-php

This is a usable but very young package with solid basic transparency: it includes a license file, README, source layout, examples, and a substantial test suite, and the repository has received 52 commits in the last 3 months. However, it has only one release at version 0.0.1, all recent commits come from one contributor, and the repository has no security policy or security-scanning tooling. The package is not deprecated or archived, so adoption is reasonable for experimental or well-isolated use, but its maturity and maintainer-resilience risks warrant caution for critical production dependencies.

Latest 0.0.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historycaution

The package is only 33 days old and has a single release, so there is little evidence of release-process maturity or long-term maintenance.

Repo bus factorcaution

All 52 recent commits came from one contributor, creating a material continuity and handoff risk for a user-owned project.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected; this is a hygiene gap for supply-chain assurance.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and disclosure expectations undocumented.

Version stabilitycaution

Version 0.0.1 is an early, non-stable-major release, which signals API and behavior may change substantially before maturity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Henrik Hautakoski

Direct Dependencies

DependencyLast ReleaseScore
illuminate/collections
Version >=10.0
shufflingpixels/php-io
Version =0.0.5

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform