Package Health

simp/pindrop

This release appears usable and actively maintained, with 25 releases over about 5 months, a recent release, stable versioning, a non-archived repository, matching package documentation, tests, a changelog, and a clear MIT license. However, the project is still relatively young, all 24 recent commits come from one contributor, the package has a substantial runtime dependency surface, install and update lifecycle scripts require review, and there is no security policy or automated security scanning. Overall, it is a reasonable dependency for developers who can accept single-maintainer and security-process risk, but it is not yet a low-risk, broadly resilient project.

Latest v4.0.4PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 24 runtime dependencies and only 1 development dependency. This broad runtime surface increases transitive maintenance and update exposure, even though the signal does not show any specifically problematic dependency.

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These increase installation complexity and deserve review because they execute during dependency operations, although this signal alone does not establish an unsafe health verdict.

Maintainerscaution

Only one account has registry publish access. This is a limited publishing resilience signal, and there is no organization backing shown to compensate for that concentration.

Project backingcaution

The repository owner is a user account rather than an organization, so the single-contributor and single-publisher concentration risks are not visibly offset by institutional backing.

Repo bus factorcaution

One contributor made all 24 commits in the last 3 months, creating a severe concentration risk with no second active contributor or organization-owned repository to compensate.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

CHANCENY

Direct Dependencies

DependencyLast ReleaseScore
mpdf/mpdf
Version ^8.3
twig/twig
Version ^3.0
filp/whoops
Version ^2.18
simp/router
Version ^1.1.5
react/socket
Version ^1.17.0

Weekly Downloads

Info

Last Published
17 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform