Package Health

rimba/lms

rimba/lms v1.4.6 appears usable and actively maintained, with 27 releases over 41 days, a stable non-prerelease version, recent repository activity, organization backing, and no deprecation or archival indicators. However, it is still a young package, all 25 recent commits come from one contributor, the artifact and repository contain no tests or changelog, the repository has no security scanning or security policy, and its release workflow grants top-level write permissions. These factors make it a reasonable dependency with meaningful maintenance and supply-chain hygiene concerns that should be monitored.

Latest v1.4.6PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

The package and repository have no README, tests, or changelog. GitHub Releases provide some release communication, but the absence of tests and user-facing documentation remains a genuine transparency and maintenance gap.

Release historycaution

The package is young at 41 days old but has 27 releases, with a median interval of about 20 hours. This demonstrates active publishing, although the short history limits evidence of long-term maintenance.

Repo bus factorcaution

One contributor made all 25 commits in the last 3 months, creating a genuine continuity risk. Organization backing partially compensates because maintenance can potentially be handed off, but no second active contributor is evidenced.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counters provide no external adoption signal for this young package.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured. The missing scanning reduces repository hygiene and supply-chain transparency, though it is not evidence of malicious behavior.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

BIT Ecosystem

Direct Dependencies

DependencyLast ReleaseScore
rimba/dms
Version ^1.3
rimba/foundation
Version ^1.3

Weekly Downloads

Info

Last Published
14 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform