Package Health

sioweb/hrworks

The README, matching repository, and GitHub release make the package understandable to adopt. Its single-maintainer project has seen no commits or releases for about six years, and the license metadata does not match the artifact license.

Latest 0.1.2PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

56

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published about six years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a package users may need to keep compatible with current systems.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months. Combined with the old last release, this indicates that maintenance capacity has effectively stopped.

Licensecaution

The package declares WTFPL, while the artifact license file was recognized as Unlicense. License files exist in both the artifact and repository, but the mismatch creates avoidable legal ambiguity.

Project backingcaution

The repository is owned by a personal user account rather than an organization, so the single registry maintainer represents a genuinely thin backing structure.

Repo issue activitycaution

There are no open issues or pull requests and no recent activity. This is neutral rather than positive because the project is very small and may simply be unused.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sascha Weidner

Direct Dependencies

DependencyLast ReleaseScore
symfony/dotenv
Version *
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform