Package Health

sfera/egora

Risky to depend on: this is a one-release, pre-1.0 package with no commits in the last three months and no demonstrated release continuity. Its linked repository does not match the package name or mention it, while the README describes Monolog rather than this package, creating a serious transparency concern.

Latest v0.0.1PackagistPackagist

28%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

Only one release exists, published about 20 months ago, with no releases in the last 12 months. That provides little evidence of sustained maintenance or release continuity.

Repo commit activitydanger

The repository had zero commits and zero active maintainers in the last three months. Together with the single historical release, this indicates a high abandonment risk.

Repo package mentiondanger

The linked repository name does not match sfera/egora and its README does not mention the package. This raises a concrete concern that the package may be using an unrelated repository as its source.

Package file treecaution

The artifact and repository each contain only 14 files and the same minimal tree, which is not inherently unhealthy. Combined with the unrelated README content, however, this offers little transparent evidence about the package's own implementation.

Package scaffoldingcaution

The artifact includes a substantial README, tests, and a changelog, which is positive packaging hygiene. However, the README excerpt documents Monolog and instructs users to install monolog/monolog, so it does not credibly document this package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jordi Boggiano

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0 || ^3.0

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform