Package Health

pvsaintpe/yii2-decta-client

The repository contains only three files, with no tests or security policy, so transparency and verification are weak. MIT licensing and no install scripts reduce friction but do not offset the age and lack of activity.

Latest 1.0.0PackagistPackagist

22%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

This is the only release, published over 7 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package having received no meaningful maintenance since its 2019 release.

Package file treecaution

The package and repository each contain only three files: .gitignore, README.md, and composer.json. That is unusually sparse for a client library and leaves little implementation or verification material to inspect.

Package scaffoldingcaution

The package has a README, but it is only 19 characters long, and neither the package nor repository has tests or a changelog. Missing tests and changelog are normal packaging practice, but the extremely brief README limits consumer guidance.

Repository archivedcaution

The linked repository is not archived, which is a modest positive; however, its last push was over 7 years ago, so this does not counter the inactivity evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pavel Veselov

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version 2.0.16.1
pvsaintpe/yii2-helpers
Version *
codeception/codeception
Version 2.*
phpdocumentor/reflection
Version *

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform