Package Health

swoft-fork/redis

It includes tests, a matching Apache-2.0 license, and no install-time scripts. The repository remains unarchived, but its unpinned container image adds build-reproducibility risk.

Latest v2.1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

This is the package's only release, published about 1 year 9 months ago, with no releases in the last 12 months. That limited history provides little evidence of ongoing maintenance.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's warning that active maintenance is not guaranteed.

Security policycaution

The repository has no security policy, leaving no documented channel or process for reporting security issues. This is a transparency gap, though it does not by itself show abandonment.

Workflow auditcaution

Both workflows were analyzed completely, but all 5 action references are unpinned and the audit found a high-confidence unpinned container image. This weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
swoft-fork/framework
Version ~2.1.0
—
—
swoft-fork/connection-pool
Version ~2.1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform