Package Health

railken/amethyst-skeleton

The package has an MIT license, tests, a usable README, and no install-time scripts. Its organization-backed repository and non-deprecated status do not offset the lack of recent maintenance and weak workflow pinning.

Latest v0.3.5PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The last release was about six years ago, with no releases in the past 12 months. Although the package has 48 releases overall, this strongly indicates abandonment risk.

Repo commit activitydanger

The repository had zero commits and zero active maintainers in the past three months, with the last push also about six years ago. This is strong evidence that maintenance has stopped.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, so the linked source may not clearly belong to this release. Organization ownership partially supports legitimacy but does not resolve the mismatch.

Workflow auditcaution

All six analyzed action references are unpinned, including a high-confidence high-severity unpinned container image finding. The workflows have no untrusted triggers or checkout sinks, which limits but does not remove the reproducibility risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^2.0
—
—
railken/bag
Version ^1.2
—
—
phpstan/phpstan
Version *
—
—
symfony/console
Version 4.*|5.*
—
—
laravel/installer
Version ^4.0
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform