Package Health

rezozero/xilofone-plugin

The repository is small but clearly matches the package and includes tests, a README, and organization backing. Licensing is absent, and the project has no security policy or automated security scanning, so maintenance and transparency deserve extra scrutiny.

Latest 1.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Dependency profilecaution

The plugin has nine runtime dependencies, including Composer and HTTP interfaces, which is a relatively involved runtime profile for a small plugin. The dependencies are consistent with its documented translation-fetching role, so this is only a modest complexity concern.

Licensecaution

No license is declared, no license file is present in the package, and no repository license file was detected. Without licensing terms, depending on the package creates a material legal and transparency gap.

Release historycaution

The package is mature at about three years old, but it has only four releases and one release in the last 12 months, with a median interval of about 440 days. That indicates a slow cadence rather than abandonment by itself.

Repo commit activitycaution

No commits or active maintainers were recorded in the last three months. Although a recent release exists, the lack of current development activity raises maintenance risk.

Repo popularitycaution

The repository has zero stars and forks and only two watchers. This shows limited external adoption, but popularity is supporting evidence and does not outweigh the package's direct project evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/dotenv
Version >=5.4
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
composer/composer
Version >=2.2
—
—
php-http/discovery
Version ^1.19
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform