Package Health

pronovix/monorepo-helper

The package is clearly identified, licensed, documented, and backed by an organization with a long release history. However, no commits or active maintainers were observed in the last three months, and the repository has no security scanning or security policy.

Latest 5.3.0PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance concern, even though the registry shows frequent releases.

Repo toolingcaution

The project uses Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.

Security policycaution

No repository security policy was found. For a Composer plugin that runs as part of dependency installation, this reduces transparency around vulnerability reporting.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
phlak/semver
Version ^4.0
—
—
symfony/finder
Version ^7.2
—
—
symfony/filesystem
Version ^7.2
—
—
pronovix/composer-logger
Version ^5.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform