Package Health

rejoice/framework

Its MIT licensing and matching repository make provenance and reuse straightforward. The very small public footprint and missing security policy add practical uncertainty for a framework.

Latest v0.1.5PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published on May 10, 2021, and there have been no releases in the last 12 months. This is strong evidence of abandonment for a framework dependency.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release hiatus. The organization-owned repository provides context but does not compensate for absent recent work.

Package scaffoldingcaution

The package includes a README and has a GitHub release for this version. No tests or changelog are not gaps in the published artifact, though the README is only 105 characters for a framework package.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 2 watchers. Popularity is not decisive, but this very small footprint provides little supporting evidence of broad adoption or review.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are configured. That reduces ongoing supply-chain hygiene for a package with many runtime dependencies.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Prince Damien Dorcis-Akpaglo

Direct Dependencies

DependencyLast ReleaseScore
psy/psysh
Version ^0.10
prinx/dotenv
Version ^0.4
prinx/notify
Version ^0.0
prinx/os-utils
Version ^0.0
prinx/phputils
Version ^0.0

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform