Package Health

reliese/dependency

The MIT license, release notes, and matching repository make the package straightforward to inspect. Its maintenance appears to have stopped after March 2021, leaving a small codebase with no recent commits or security tooling.

Latest v1.1.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historycaution

The package has only two releases, both published on March 11, 2021, with no release in more than five years. This is strong evidence of abandonment risk, although the stable v1.1.0 release provides some maturity.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months. Combined with the repository's 2021 last push, this indicates sustained inactivity rather than a short pause.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, secondary to the much stronger inactivity evidence.

Repository archivedcaution

The linked repository is not archived, but it was last pushed on March 11, 2021. The unarchived status is positive, while the old last-push date supports the maintenance concern.

Security policycaution

The repository has no security policy. For a small dependency container this is a transparency gap, though it is less significant than the lack of recent development.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Cristian Llanos

Direct Dependencies

DependencyLast ReleaseScore
reliese/component-dependency
Version ^1.0

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform