Package Health

seiger/slang

This is a generally healthy, actively maintained release with a clear license, stable versioning, regular recent releases, an active non-archived repository, repository tests, and a package/repository identity match. The main reservations are that publishing access is concentrated in one registry maintainer, the package uses a post-autoload-dump lifecycle script, the repository lacks security-scanning tooling and a security policy, and one workflow grants top-level write permissions. These are meaningful transparency and operational-hygiene gaps, but they do not outweigh the strong recent release and repository activity or indicate abandonment.

Latest v1.1.3PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump install-time script increases supply-chain and installation complexity, so consumers should review what it executes before adoption.

Maintainerscaution

Only one account has registry publishing access. This is a real publishing-continuity concern for a user-owned project, although repository activity shows that the project is currently maintained.

Project backingcaution

The repository is owned by a user account rather than an organization, so there is no organizational maintenance buffer to offset the concentrated registry and repository ownership.

Repo bus factorcaution

Two contributors were active recently, with the leading contributor responsible for about two-thirds of commits. This is somewhat concentrated, but the second active contributor provides partial resilience.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanning layer reduces assurance around dependency and release hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Serhii Korneliuk

Direct Dependencies

DependencyLast ReleaseScore
evolution-cms/evolution
Version ^3.3
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform