Package Health

topthink/think-migration

Organization backing, a clear license, and a matching source repository provide useful transparency. The small artifact, missing repository tests and security policy, and install-time scripts warrant extra operational review.

Latest v3.1.1PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts, adding installation-time behavior that should be understood before use. No provided signal shows those scripts are harmful, so this is a caution rather than a severe risk.

Release historycaution

The package has 21 releases since March 2016 but none in the last three years, with the latest published in September 2023. This is a meaningful maintenance concern despite its established history.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Although the last push was in March 2025, the recent inactivity raises abandonment risk.

Repo issue activitycaution

There are 23 open issues and 9 open pull requests, but no issues or pull requests were opened or merged in the measured month. This supports caution about current responsiveness.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a hygiene gap, not evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

yunwuxin

Direct Dependencies

DependencyLast ReleaseScore
topthink/framework
Version ^6.0 || ^8.0
—
—
topthink/think-helper
Version ^3.0.3
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform