Package Health

roots/soil

Release activity stopped over four years ago, and the package also resembles a more established package while borrowing its identity. MIT licensing, tests, documentation, and a matching organization repository are positives, but they do not offset the maintenance risk.

Latest 4.1.1PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

33

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Name lookalikedanger

The package borrows the identity of roots/wp-config, has no fork disclosure, and is much less downloaded than that package; consumers may have intended the lookalike instead.

Registry deprecationdanger

Packagist marks the entire package as abandoned and points consumers to roots/acorn-prettify, making continued dependency use a serious lifecycle risk.

Release historydanger

The latest release was published in August 2022, with no releases in the following four years; this strongly indicates the package has been left behind.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers over the last three months, consistent with the archived and abandoned status.

Repository archiveddanger

The linked GitHub repository is archived, so it is no longer an actively maintained upstream despite having been pushed in January 2024.

Vulnerabilities

TitleVersionsSeverity
CVE-2022-4524
roots/soil is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.1.0.
0.0.0 - 4.1.0
Medium

Package versions

Maintainers

Ben Word
Scott Walkinshaw
QWp6t

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform