Package Health

proxiblue/newrelic

The repository is still present, the package has documentation and release notes, and it is not deprecated. The license files conflict with the declared license, while recent commit and release activity is absent and no security tooling or policy is provided.

Latest 1.0.7PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest registry release was 1.0.7 on March 2, 2017, with no releases in the last 12 months. This substantially raises maintenance and compatibility risk, although the linked repository was pushed more recently.

Licensecaution

The artifact contains a license file and the repository also has one, but the manifest declares OSL-3.0 while the detected license is GPL-3.0. That mismatch requires legal clarification before adoption.

Repo commit activitycaution

There were zero commits and zero active maintainers in the three months before collection. Combined with no recent registry releases, this indicates weak current maintenance despite the later repository push.

Repo toolingcaution

The repository uses Composer, but no security scanning tool was detected. This is a transparency and hygiene gap, not evidence that the package is unsafe.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations unspecified. This lowers transparency for a package integrated into production systems.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Lucas van Staden

Direct Dependencies

DependencyLast ReleaseScore
magento-hackathon/magento-composer-installer
Version *
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform