Package Health

soprex/findologic-test-lib

The artifact is small and clearly matches its repository, with no install scripts or deprecation notice. The unresolved MIT-versus-GPL licensing mismatch and absent security policy add adoption friction.

Latest 0.0.9.16PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The latest release was published in May 2016, and there have been no releases in roughly 10 years. This is strong evidence of abandonment for a dependency, despite 25 historical releases.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the lack of releases for about 10 years. This materially increases abandonment risk.

Licensecaution

The manifest declares MIT, but the artifact license file is detected as GPL-3.0. Although a license file exists, the mismatch creates material uncertainty about the terms under which the package may be used.

Project backingcaution

The package and repository are owned by the same individual account, supporting identity continuity but not organizational maintenance capacity. Combined with one registry maintainer and long inactivity, backing appears thin.

Repo toolingcaution

Composer is used as a build tool, which fits the package ecosystem, but no security-scanning tooling is present. The missing scanning is a modest hygiene gap rather than evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Soprex

Direct Dependencies

DependencyLast ReleaseScore
phpunit/phpunit
Version 4.8.*
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform