Package Health

toll-mesh/cache

This release has solid structural and transparency indicators: it is Apache-2.0 licensed, includes a README and tests, has a substantial repository tree, uses Composer, has no install-time lifecycle scripts, is not deprecated or archived, and is backed by an organization. However, it is extremely new (two releases within roughly 17 hours), with only one commit and one active contributor in the observed three-month window, all activity concentrated in that contributor. The repository has no security policy, no security-scanning tooling, and two publishing workflows grant top-level write permissions. The package is therefore usable but should be adopted cautiously until its maintenance history, contributor base, and release/security practices mature.

Latest v1.1.1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historycaution

The package is effectively brand new: it has only two releases and an age of zero recorded days, with releases separated by about 17 hours. This leaves maintenance reliability and release-process maturity largely unproven.

Repo bus factorcaution

One contributor accounts for 100% of the single observed commit. Organization backing partly mitigates handoff risk, but no second active contributor is shown, so the current operational bus factor remains weak.

Repo commit activitycaution

Only one commit and one active maintainer are observed over three months. Although the project is new, this provides very little evidence of sustained maintenance capacity.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counters provide no external adoption or community validation for this very new package.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are detected. The build setup is positive while the absent security automation is a genuine hygiene gap for a package distributed through multiple publishing workflows.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

TollMesh Team

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.4
—
—

Weekly Downloads

Info

Last Published
23 days ago
Created
24 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform