Package Health

spereten/string

The package is very small and gives consumers no README or license information. Its simple dependency set and matching repository reduce complexity, but there is little evidence of ongoing project activity.

Latest v1.1.0PackagistPackagist

35%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

Only two releases appeared on 24 November 2022, with no release in nearly four years and none in the last 12 months. This is strong evidence of abandonment risk despite the stable 1.1.0 version.

Licensecaution

The package declares no license, includes no license file, and the repository has no license file. This leaves legal reuse unclear and is a material transparency concern.

Maintainerscaution

A single registry maintainer is consistent with an independently owned package, but it leaves the project dependent on one publisher and provides little resilience if they stop maintaining it.

Package file treecaution

The complete package contains only four files: composer metadata, two source files, and a gitignore. This supports a narrow scope but provides little project documentation or evidence of engineering depth.

Package scaffoldingcaution

The published artifact has no README, while tests and a changelog are normally repository concerns and are not expected in every package artifact. The missing README still makes this small library harder to evaluate and consume.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Artem Aleinik

Direct Dependencies

DependencyLast ReleaseScore
symfony/polyfill-mbstring
Version ^1.27
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform