Package Health

temando/packagist-test

Risky to depend on: this is a minimal package with no license and no activity since March 2021. It is not deprecated or archived, but its tiny repository and long-term inactivity make maintenance and reuse a liability.

Latest 1.0.6PackagistPackagist

28%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package is over five years old, has only 3 releases, and has had no release in the last 12 months. This is strong evidence of abandonment rather than an actively maintained dependency.

Repo commit activitydanger

The repository has recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the last push occurring in March 2021. The prolonged lack of development materially increases maintenance risk.

Licensecaution

No declared license or license file was found in the package or repository. That leaves developers without clear permission to use, modify, or redistribute the dependency.

Maintainerscaution

The registry lists one publishing maintainer. The organization-owned repository provides some backing context, so the short registry list is not itself a severe concern, but it offers little evidence of an active maintainer base.

Package file treecaution

The package and repository each contain only composer.json, showing an unusually minimal project with little visible implementation or supporting material. This may be intentional for a test package, but it provides very limited transparency for a dependency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Keith Bentrup

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform