Package Health

sallycms/be-search

Its small, focused artifact has a modest dependency surface and no install-time scripts. Organization ownership and a matching repository improve traceability, but this release should be treated as legacy software.

Latest v3.0.0PackagistPackagist

35%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The latest release was published more than 10 years ago, with no releases in the last 12 months. That long lapse is strong evidence of abandonment risk despite a history of nine releases.

Repo commit activitydanger

There were no commits or active maintainers in the last three months, and the repository was last pushed nearly 10 years ago. This is a substantial abandonment risk.

Package scaffoldingcaution

The package has no README, while tests and a changelog are absent from the artifact and repository; the latter two are normal for published packages. Missing consumer documentation is a minor transparency concern for a backend add-on.

Repo popularitycaution

The repository has zero stars and one fork, providing little supporting evidence of adoption or an active user community. Popularity is only supporting evidence, so this is a modest concern.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling was detected. The missing scanning is a hygiene gap rather than a standalone reason to reject the release.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

webvariants GbR

Direct Dependencies

DependencyLast ReleaseScore
sallycms/sallycms
Version >=0.10,<0.11
sallycms/composer-installer
Version ~1.1

Weekly Downloads

Info

Last Published
10 years ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform