Package Health

tohidplus/paravel

Risky to adopt: the latest release was published nearly six years ago and the repository has had no commits or active maintainers in the last three months. It is licensed, clearly backed by the matching repository, and has a usable README, but maintenance appears effectively abandoned.

Latest 2.0.2PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has had no releases in the last 12 months, with the latest release nearly six years ago. The six-release history shows an established package but does not offset the prolonged inactivity.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, providing strong evidence that maintenance has stopped.

Maintainerscaution

Only one registry account can publish releases, leaving a thin maintainer base and limited apparent continuity for a package that has already been inactive for years.

Repo toolingcaution

Composer build tooling is present, but no security scanning tooling was detected. That leaves less evidence of ongoing automated maintenance.

Repository archivedcaution

The repository is not marked archived, which is a positive sign, but its last push was nearly six years ago; the non-archived status does not compensate for the lack of recent activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tohid Dadashnejad

Direct Dependencies

DependencyLast ReleaseScore
jeremeamia/superclosure
Version ^2.4
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform