Package Health

primer/phpqrcode

This release is usable and reasonably transparent, with a stable 1.6.0 version, an explicit LGPL-2.1-or-later license, no deprecation, no install-time scripts, a matching repository, and recent commit activity. However, the project is very young at 35 days, has no visible adoption metrics, all 42 recent commits come from one contributor, and lacks a security policy or security-scanning tooling. Repository tests and build tooling provide useful supporting evidence, but the concentrated maintainer base and limited maturity make this a cautionary dependency rather than a fully established one.

Latest 1.6.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Project backingcaution

The source repository is owned by the individual user primer97, not an organization, so the project has limited demonstrated institutional backing.

Release historycaution

Five releases in 35 days with a median interval of about 7.5 days shows active early development, but the short history provides little evidence of long-term maintenance maturity.

Repo bus factorcaution

All 42 recent commits came from one contributor, creating a genuine continuity and handoff risk. The repository is user-owned rather than organization-backed, so there is no provided project-backing evidence to offset this concentration.

Repo issue activitycaution

There are no open issues or pull requests and no activity in the last month; this is not inherently negative for a small library, but it provides no evidence of an active user or review community.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the complete absence of adoption signals modestly reduces confidence in project maturity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Fabien

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
18 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform