Package Health

tavrin/sirius

The package has a substantial README, a matching repository, and a clear MIT license. Its single release and lack of commits for nearly five years leave maintenance and compatibility risks for a framework dependency.

Latest v0.1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has only one release, published nearly five years ago, with no releases in the last 12 months. That is strong evidence of an immature or abandoned dependency.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no recent maintenance capacity.

Repo popularitycaution

The repository has one star and no forks, offering little evidence of broad community use or external review. Low popularity is supporting evidence rather than decisive by itself.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a hygiene gap, not evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Etienne Doux - Tavrin

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.0
ramsey/uuid
Version ^4.1
vlucas/phpdotenv
Version ^5.3
composer/composer
Version 2.1.x-dev
phpmailer/phpmailer
Version ^6.3

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform