Package Health

sudiptochoudhury/php-clubspeed-events-karting-enterprise

The package is clearly identified, licensed, and easy to inspect, with a small dependency set and no install-time scripts. Its single-person ownership, lack of recent activity, and missing security practices increase the risk of relying on it for new work.

Latest v0.0.19PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. Because the repository is owned by an individual rather than an organization, there is little visible publishing redundancy.

Project backingcaution

The package and repository are both owned by the same individual account, with no organizational backing shown; this provides less continuity than an organization-supported project.

Release historycaution

The package has 18 releases since November 2018, but none in the last 12 months; the latest release was over two years ago, indicating sustained inactivity.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months, consistent with the release gap and indicating that maintenance has effectively paused.

Repo toolingcaution

Composer is used for builds, but no security scanning tool is configured. That is a meaningful security-process gap for a package intended to be consumed as a library.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sudipto Choudhury

Direct Dependencies

DependencyLast ReleaseScore
sudiptochoudhury/php-api-client-forge
Version dev-master
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform