Package Health

sendaxe/senda-gnre

The project has useful documentation, tests, release notes, and a matching source repository. Its last release was over eight years ago, repository commits stopped about seven years ago, and no security policy or scanning is present.

Latest v2.0.0PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The package has only 4 releases and none in the last 12 months; the latest release was over eight years ago. This is strong evidence of abandonment risk for a maintained integration library.

Repo commit activitydanger

There were 0 commits and 0 active maintainers in the last 3 months. Combined with the old last push, this indicates that maintenance has effectively stopped.

Lifecycle scriptscaution

An install-time post-root-package-install script is present. This adds some installation behavior to review, but the signal alone does not show unsafe or unusual actions.

Project backingcaution

The repository is owned by the same individual account associated with the package namespace, providing a consistent ownership link. It does not show organizational backing or a broader maintenance team.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are reported. The missing scanning is a hygiene gap, while the build tooling itself is appropriate for this package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Senda XE

Direct Dependencies

DependencyLast ReleaseScore
dompdf/dompdf
Version 0.6.*
—
—
smarty/smarty
Version ~3.1
—
—
league/flysystem
Version ~1.0
—
—
vlucas/phpdotenv
Version ~2.2
—
—
myclabs/deep-copy
Version 1.7.*
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform