Package Health

tomahawk/framework

The MIT license, included tests, and matching organization-backed repository improve transparency. Its older PHP-era dependency set and lack of a security policy add maintenance concerns, even though the package is not deprecated or archived.

Latest 2.1.1PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has 59 releases, but its latest release was in February 2018 and it had no releases in the last 12 months, showing prolonged inactivity.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's long release gap and significant abandonment risk.

Dependency profilecaution

The package declares 28 runtime dependencies, including legacy PHP extensions and older framework components, which increases compatibility and maintenance burden for adopters.

Repo issue activitycaution

There were 10 open issues but no new or closed issues and no pull requests in the last month, indicating that reported work is not being actively handled.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are configured. The missing scanning is a modest hygiene gap rather than proof of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tom Ellis

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ~1.0.0
—
—
twig/twig
Version ~1.28|~2.0
—
—
doctrine/orm
Version ~2.3
—
—
doctrine/dbal
Version ~2.3
—
—
predis/predis
Version ~1.0
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform