Package Health

techlify/asset-management

Risky to depend on: this package has had only one release, published over seven years ago, and its linked repository stopped receiving updates shortly afterward. The repository also does not identify or document this package, creating uncertainty about whether it is the intended source.

Latest 0.2.0PackagistPackagist

35%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

57

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

There is only one release, and no release has been published in more than seven years. That strongly suggests abandonment and leaves no demonstrated maintenance cadence.

Repository archiveddanger

The repository is not archived, but its last push was more than seven years ago, so the active status does not compensate for the long period without updates.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. This weakens source transparency and raises uncertainty about whether the repository actually backs this release.

Repo toolingcaution

Composer is used for the build, but no security scanning tools are configured. This is a modest transparency gap, secondary to the package's much more significant maintenance concerns.

Security policycaution

The repository has no security policy. For a package that can be integrated into applications, this makes vulnerability reporting less clear, although it is less serious than the lack of ongoing maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Techlify Inc.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform