Package Health

sbwerewolf/fias-gar-data-import-tool

The package includes tests, a clear README, and a matching source repository. Its one-person ownership and missing security policy make long-term support less certain.

Latest v1.0.4PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

Only one registry publishing maintainer is listed, so continuity depends on a single individual. The linked repository and package identity match, providing some transparency but not redundancy.

Release historycaution

The latest release was over a year ago, and there were no releases in the last 12 months. The package has only five releases overall, limiting evidence of an active maintenance cycle.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last three months, despite the source repository being available and the latest release having been published over a year earlier.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a modest hygiene gap rather than evidence of unsafe code.

Security policycaution

The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, though it does not by itself make the release unfit.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nikolay Volkhin

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
sbwerewolf/batch-file-scripting
Version ^3.0
—
—
sbwerewolf/json-serialize-trait
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform