Package Health

swoft-fork/tcp

The source tree includes tests and an Apache-2.0 license, and the repository is not archived. All five workflow actions are unpinned, adding avoidable build-integrity risk.

Latest v2.1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

80

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

This package has only one release, published about 1 year 9 months ago, with no releases in the last 12 months. That provides little evidence of ongoing maintenance.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the long release gap and indicating likely abandonment risk.

Security policycaution

The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less serious than the lack of recent development.

Workflow auditcaution

All 5 of 5 analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene. No untrusted checkout, script injection, or high-severity audit finding was detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
swoft-fork/stdlib
Version ~2.1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform