Package Health

scriptdevelop/meta-catalog-manager

The package is well documented, licensed, and includes a changelog. Install-time scripts and the missing security policy add modest supply-chain and transparency concerns.

Latest v1.0.71PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts, which increase installation-time behavior and supply-chain exposure; the signal provides no evidence that these scripts are unsafe.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to offset the concentrated maintenance base.

Repo bus factorcaution

One contributor made 100% of the commits in the last three months, leaving maintenance dependent on a single active contributor.

Repo commit activitycaution

Only one commit was recorded in the last three months, indicating limited recent maintenance activity despite the active registry release history.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected, leaving an avoidable gap in repository hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Wilfredo Perilla

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.0
—
—
laravel/framework
Version ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform