Package Health

rcm/responsive-hover-image

Risky to adopt: the package has had no release or commit activity since April 2019, leaving it effectively unmaintained. Its tiny artifact and repository that does not clearly reference the package add transparency concerns, despite having a declared license and no install-time scripts.

Latest 1.0.3PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

61

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historydanger

The latest release was about 7 years ago, with no releases in the last 12 months and only three releases overall. That strongly suggests the package is no longer actively maintained, although the stable 1.0.3 version may be acceptable for a frozen integration.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last 3 months, consistent with the last push being about 7 years ago. This is the clearest evidence that maintenance capacity has collapsed.

Package file treecaution

The artifact and repository each contain only four files, including a template and block metadata. That may fit a small block package, but it provides little visible project surface for assessing maintenance or documenting use.

Package scaffoldingcaution

A README is present, but it contains only 29 characters and there are no tests or changelog. Missing tests and changelog are normal for published artifacts, while the nearly empty README leaves consumers with little integration guidance for this block.

Project backingcaution

The repository is owned by an organization, which provides some project backing and makes a short registry maintainer list unsurprising. However, the backing has not translated into recent release or commit activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform