Package Health

shaquer/grumphp-config

Its README and matching seven-file repository make the configuration easy to understand, and it has no install-time scripts. The single maintainer, absent security policy, and nine runtime dependencies leave little evidence of ongoing support.

Latest 4.1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has 38 releases since March 2019, but its latest release was in June 2022 and it had no releases in the following 12 months, indicating prolonged abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and limited evidence of current maintenance.

Dependency profilecaution

This focused configuration package declares nine runtime dependencies, including several analysis and linting tools, increasing maintenance exposure even though the dependencies fit its stated purpose.

Licensecaution

Neither the package nor the linked repository provides a license declaration or license file, leaving the terms for using this dependency unclear.

Repo popularitycaution

The repository has only 1 star and 2 forks, providing little supporting evidence of broad review or community maintenance; this is secondary to the stronger inactivity signals.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Erik Seifert

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^2.0
drupal/coder
Version ^8.3
phpro/grumphp
Version ^1.1
phpstan/phpstan
Version ^1.7.8
friendsoftwig/twigcs
Version ^6

Weekly Downloads

Info

Last Published
4 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform