Package Health

rudrax/smarty

The package declares MIT licensing, but its included notice refers to LGPL and the repository has no license file. It also lacks security scanning and has no recent workflow or release documentation to offset the maintenance concerns.

Latest v3.1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

Only three releases were published, with no releases in the last 12 months; the latest registry release is roughly 11 years old. This is strong evidence of abandonment for a package intended as an application dependency.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, after the repository's last push roughly 11 years ago. This is the clearest evidence that fixes and maintenance are unlikely.

Licensecaution

The manifest declares MIT, so the release is not unlicensed, but the packaged README excerpt contains an LGPL notice and no license file was found. That creates a meaningful licensing ambiguity for consumers.

Project backingcaution

The repository owner is an organization, which can provide some backing beyond an individual publisher. However, the observed release and commit activity shows no active maintenance capacity.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with an inactive project, though the absence of open work is not harmful by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
12 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform