Package Health

rotexsoft/slim3-skeleton-mvc-tools

A single contributor made all five recent commits, and the linked repository does not name or mention this package. Tests, release notes, organization ownership, and active publishing provide useful continuity; workflow references remain unpinned and no security policy is published.

Latest 7.2.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo bus factorcaution

One contributor made all 5 commits in the last 3 months, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity, but no second recent contributor is shown.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Although this can occur with related projects, the absence of either identity link warrants caution about repository association.

Security policycaution

No repository security policy was found. For a maintained library this is a modest transparency gap, though it is not evidence of abandonment by itself.

Workflow auditcaution

The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both action references are unpinned. The missing top-level permissions block is acceptable on its own; unpinned actions remain a mild reproducibility and supply-chain hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rotimi Adegbamigbe

Direct Dependencies

DependencyLast ReleaseScore
slim/slim
Version ^4.10
nyholm/psr7
Version ^1.8
vespula/log
Version ^3.0.0
vespula/auth
Version ^4.0.0
pimple/pimple
Version ^3.5

Weekly Downloads

Info

Last Published
2 months ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform