Package Health

rgeraads/exchangerate

The project includes tests, a README, and a license file, but its declared proprietary license conflicts with the MIT license found in the artifact. No security policy or scanning tooling is present, adding uncertainty for a long-unmaintained dependency.

Latest 2.0PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published about 8 years ago, with only two releases overall and none in the last 12 months. That is strong evidence of abandonment for a library that retrieves external exchange-rate data.

Repo commit activitydanger

The repository has had no commits or active maintainers in the last 3 months, and was last pushed about 7 years ago. The lack of recent development materially increases maintenance and compatibility risk.

Licensecaution

The artifact contains an MIT license file and the repository also has a license file, so the release is licensed. However, the manifest declares it as proprietary while the detected license is MIT, creating a material licensing ambiguity.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, especially alongside the absence of recent activity.

Security policycaution

The repository has no security policy. For a package that contacts external exchange-rate services, this leaves vulnerability-reporting and maintenance expectations unclear.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
moneyphp/money
Version ^3.1
—
—
guzzlehttp/guzzle
Version ^6.3
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform