Package Health

quantaforge/framework

The source includes tests and a changelog, and installation has no lifecycle scripts. The single maintainer, absent security policy, and license mismatch leave limited ongoing assurance.

Latest v1.0.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Licensecaution

The artifact contains MIT license files and the repository also has a license file, but the manifest declares the package proprietary. That mismatch requires legal clarification before adoption.

Maintainerscaution

Only one registry account has publish access. Organization backing provides some context, but the observed lack of recent commits means it does not compensate for the thin active-maintainer evidence.

Release historycaution

This package has made only one release, on October 14, 2023, with none in roughly 2 years and 11 months. That strongly raises abandonment risk for a framework dependency.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and weak evidence of current maintenance.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. With no recent commits or releases, the inactivity is more consistent with an inactive project than with efficient maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tomáš Selič (Smisch-DEV)

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0|^2.0|^3.0
brick/math
Version ^0.9.3|^0.10.2|^0.11
ramsey/uuid
Version ^4.7
symfony/uid
Version ^6.2
symfony/mime
Version ^6.2

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform