Package Health

tangible/rule-engine

This is a young but currently active package with four releases over 99 days, a repository pushed within the last day, and six recent commits from two contributors under an organization-owned project. Its small, coherent eight-file tree and absence of install-time scripts reduce complexity and operational risk. However, the release has no README, tests, or changelog in either the artifact or repository, and the repository has no security policy or security-scanning tooling; these are meaningful transparency and maintenance gaps for a package that may be adopted as a library. The package remains pre-1.0 and has limited ecosystem evidence, so it is usable but should be adopted with normal dependency-review and testing precautions.

Latest 0.1.3PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

Neither the artifact nor repository contains a README, tests, or changelog, leaving usage guidance, regression coverage, and release documentation unsubstantiated. The absence of repository tests is not compensated by the provided signals.

Repo issue activitycaution

There are no open issues and no issue or pull-request activity in the last month. This is ambiguous for a young, small project: it offers no evidence of community support, but also no unresolved maintenance queue.

Repo popularitycaution

The repository has zero stars, forks, and watchers, so there is little external adoption evidence. Popularity is supporting evidence only, and the recent activity and organization backing compensate for this limited footprint.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tooling is present. The build setup is appropriate for the ecosystem, while the missing security automation is a modest hygiene gap.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and maintainer response expectations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Team Tangible

Direct Dependencies

DependencyLast ReleaseScore
tangible/ast
Version ^0.1.2

Weekly Downloads

Info

Last Published
22 days ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform