Package Health

sparknets/cateringpos

The package has a very small footprint and limited project safeguards, which makes long-term support harder to assess. Its stable version and minimal runtime dependency help, but the maintenance picture remains weak.

Latest v1.0.15PackagistPackagist

35%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

61

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The latest release was published on May 31, 2021, and there have been no releases in the last 12 months. A five-year release gap is strong evidence of abandonment risk, despite 14 releases during the initial period.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months. Combined with the last push in 2021, this indicates a serious maintenance and abandonment risk.

Licensecaution

The artifact declares Apache-2.0 and includes a license file, so licensing is present. However, the detected MIT license conflicts with the declaration, creating a transparency concern.

Maintainerscaution

Only one registry account has publish access. A single maintainer is not inherently unhealthy, but it offers little publishing redundancy when the repository also shows no recent activity.

Package file treecaution

The artifact is small and contains Composer metadata plus interface and helper source files, but it also includes committed vendor files and IDE metadata. This is untidy packaging rather than a severe dependency risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

张海

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform