Package Health

techart/bxapp

Usable with caveats: it has frequent releases and an active, unarchived repository, but the repository shows no commits in the last three months and has no tests or security policy. Its zero-star profile and broad runtime dependency set add uncertainty for long-term support.

Latest 0.9.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package declares 15 runtime dependencies and no development dependencies, creating a relatively broad runtime supply-chain and compatibility surface. The dependency set is consistent with a framework package, but the lack of dev dependencies also provides little evidence of a maintained test or development setup.

Maintainerscaution

One registry publishing account is listed, but the repository is owned by the same named individual rather than an organization. This leaves a thin apparent maintainer base and increases continuity risk.

Package scaffoldingcaution

A README and changelog are present in both the artifact and repository, but the README has zero recorded characters and neither side contains tests. The changelog helps transparency, while the absence of tests remains a maintenance gap.

Project backingcaution

The registry namespace and repository owner match, which supports that the source repository belongs to the package. The owner is a user account, so there is no organization-level backing to offset the thin maintainer base.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last three months, despite a release being published recently. This disconnect raises a meaningful concern about source maintenance and release provenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Techart

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^7.0
—
—
dompdf/dompdf
Version ^3.0
—
—
eftec/bladeone
Version ^4.0
—
—
iio/libmergepdf
Version ^4.0
—
—
illuminate/view
Version ^11.0
—
—

Weekly Downloads

Info

Last Published
12 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform