Package Health

swoft-fork/framework

The package includes tests and a matching Apache license, but its single release and zero recent commits leave maintenance uncertain. All five workflow actions are unpinned, with no security policy or scanning; adopt only if you can accept ownership risk.

Latest v2.1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

This is the package's only release, published 643 days ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance for a framework dependency.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the one-release history, this is a substantial abandonment concern.

Security policycaution

The repository has no security policy and no security scanning tools were reported. For a framework intended to run in applications, this weakens vulnerability reporting and maintenance transparency.

Workflow auditcaution

Both workflows were fully analyzed with no dangerous triggers, sinks, or audit findings, and no top-level write permissions. However, all 5 of 5 action references are unpinned, leaving avoidable build reproducibility and action-substitution risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
swoft-fork/aop
Version ~2.1.0
—
—
swoft-fork/log
Version ~2.1.0
—
—
swoft-fork/bean
Version ~2.1.0
—
—
swoft-fork/error
Version ~2.1.0
—
—
swoft-fork/event
Version ~2.1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform