Package Health

tpf/framework

The repository has no security policy, no measured adoption, and no release or commit activity in over a year. Tests, an MIT declaration, and no install scripts provide some reassurance, but the maintenance gap remains substantial.

Latest 0.2.5PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has had no release in the last 12 months, and its latest release was about 19 months ago. Four releases in total show an earlier release history, but the current gap materially raises abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no observed recent maintenance.

Repo popularitycaution

The repository has 0 stars, 0 forks, and 1 watcher, providing little community evidence to compensate for the lack of recent project activity.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. This is a moderate transparency and maintenance gap rather than evidence of an unsafe release by itself.

Security policycaution

No security policy was found in the linked repository, leaving vulnerability reporting and response expectations unclear for a framework handling authentication, mail, and database features.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexandr Popov
TPF Framework

Direct Dependencies

DependencyLast ReleaseScore
jwt/php-jwt
Version *
—
—
monolog/monolog
Version ^3.8
—
—
firebase/php-jwt
Version ^6.9
—
—
phpmailer/phpmailer
Version ^6.8
—
—
symfony/http-foundation
Version ^5.3|^6.4
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform