Package Health

tochka-developers/jsonrpc-smd-converter

It is MIT-licensed, documented, and tied to an organization-owned repository. The tiny user base and absent security tooling provide little evidence of long-term support.

Latest v0.9.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has had no release in about eight years, with only four releases total and none in the past 12 months. This is strong evidence of abandonment risk, although the repository is not archived.

Repo commit activitydanger

There were no commits and no active maintainers in the past three months, consistent with the package's last release being about eight years ago. The organization-owned repository provides some backing but does not demonstrate current maintenance.

Repo popularitycaution

The repository has only 1 star, 1 fork, and 4 watchers, providing little independent evidence of broad adoption or community support. Low popularity is supporting evidence rather than a verdict by itself.

Repo toolingcaution

Composer is used for the build, but no security scanning tools were detected. For a dependency intended for application integration, that reduces transparency around ongoing security maintenance.

Security policycaution

The linked repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This is a hygiene and transparency gap, not evidence of a vulnerability.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dmitriy Barakovskikh

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^6.3
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform