Package Health

spitfire/event

Its six-file implementation is clearly licensed and has no install-time scripts, so adoption is straightforward. The organization-backed repository and recent push provide some maintenance reassurance; pin this version and watch for a renewed release cadence.

Latest 0.1.5PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Maintainerscaution

Only one registry publishing account is listed, which is a limited publishing base. The organization-backed repository provides some compensation, but registry release continuity still depends on a narrow publisher set.

Package scaffoldingcaution

The artifact contains no README, tests, or changelog, but this is a very small six-file library and published artifacts commonly omit repository documentation and tests. The missing README is still a minor consumer-transparency gap.

Release historycaution

The package has six releases since February 2022, but none in the last 12 months and nearly two years have passed since the latest release. This weakens confidence in ongoing release maintenance.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months. Although the repository was pushed recently, the observed short-term development activity remains weak.

Repo toolingcaution

Composer is used as the build tool, providing ecosystem-appropriate project tooling, but no security scanning tool was detected. For this small package, the missing scanner is a modest hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

César de la Cal Bretschneider

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform