Package Health

smoren/yii2-event-router

It has a clear MIT license, a matching repository, and no install-time scripts. The very small implementation and lack of tests provide limited evidence for long-term reliability, despite release notes documenting this version.

Latest v0.2.0PackagistPackagist

39%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The package has only two releases, both published on December 17, 2022, with no releases in the last 12 months. This is strong evidence of abandonment risk for a package released at version 0.2.0.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, and its last push was in December 2022. The repository is not archived, but there is no observed recent maintenance to compensate.

Package file treecaution

The release contains only five files and one source file, which may reflect a deliberately small package but leaves little evidence of a mature project structure. The matching repository and README reduce concern about package provenance.

Repo popularitycaution

The repository has zero stars, one fork, and one watcher, providing little supporting evidence of community review or adoption. Popularity is only supporting evidence, so this does not independently determine the score.

Repo toolingcaution

Composer is used for the build, but no security scanning tools were found. This is a modest transparency and hygiene gap, not evidence that the release is unsafe by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Smoren

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version ~2.0.0
smoren/event-router
Version ^0.3.0

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform