Package Health

rhubarbphp/scaffold-navigation-menu

The package includes tests, release notes, a clear Apache-2.0 license, and no install-time scripts. Its last release was nearly 10 years ago, repository commits stopped about 7 years ago, and the repository does not identify the package in its README.

Latest 1.0.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was in October 2016, with no releases in the last 12 months. This long release gap materially raises abandonment risk.

Repo commit activitydanger

There were no commits or active maintainers in the last 3 months, consistent with repository inactivity for about 7 years. This is a substantial abandonment concern.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. That weakens provenance confidence, even though a subpackage can legitimately use a different repository name.

Repo toolingcaution

Composer is used for the build, but no security scanning tools are reported. The missing scanning is a modest hygiene gap, not a standalone adoption blocker.

Security policycaution

The repository has no security policy. This is a transparency gap, though it is less significant than the prolonged release and commit inactivity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
rhubarbphp/rhubarb
Version ^1.1.0
—
—
rhubarbphp/module-leaf
Version ^1.0.0@dev
—
—
rhubarbphp/module-stem
Version ^1.0.0
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform