Package Health

romanlazko/str

The README and MIT declaration make adoption straightforward, and the package has no deprecation or install-time scripts. Its four releases arrived within one day, followed by 16 months without commits or new releases; the repository also has no tests or security scanning.

Latest 1.3PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Maintainerscaution

One registry maintainer is consistent with a user-owned package, but it leaves little visible publishing redundancy when combined with the lack of recent activity.

Project backingcaution

The package and repository are owned by the same individual account, and the user-owned context fits the single maintainer. It provides less organizational continuity than a backed project.

Release historycaution

The package has four releases, but all appeared within roughly one hour and there have been no releases in the last 12 months. This concentrated launch followed by a long pause raises maintenance concern.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, consistent with the release pause and indicating no current maintenance activity.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. This is compatible with a small package, but it does not demonstrate an engaged user or maintainer community.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Roman Lazko

Direct Dependencies

DependencyLast ReleaseScore
romanlazko/support-macroable
Version >=1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform