Package Health

react-parallel/contracts

The repository includes tests, release notes, and clear organization backing. Its licensing and package identity are transparent, but the maintenance cadence and workflow hygiene warrant caution for long-lived dependencies.

Latest 2.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package defines post-install and post-update Composer scripts. Install-time scripts expand dependency-install behavior and deserve caution even though this signal does not show that they are malicious.

Release historycaution

The package has only 3 releases since February 2020, with no releases in the last 12 months and a median interval of about 901 days. This indicates a slow maintenance cadence, though the latest release is established rather than abandoned outright.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months. Although the repository is not archived, the observed recent development activity is currently paused.

Repo toolingcaution

The project uses Make and Composer build tooling, but no security-scanning tool was detected. For a small contracts package this is a modest transparency gap rather than a severe risk.

Security policycaution

The repository has no security policy. That weakens the project's documented vulnerability-reporting process, though it does not by itself show unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Cees-Jan Kiewiet

Direct Dependencies

DependencyLast ReleaseScore
wyrihaximus/pool-info
Version ^2.0.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform