Package Health

tq/shamir

This release has solid transparency and implementation hygiene: it is MIT-licensed, backed by a matching organization-owned repository with tests, security policy, Dependabot, safe workflow analysis, and a recent release. However, Packagist marks tq/shamir as abandoned and points users to teqneers/shamir, which is a major adoption risk even though the repository is not archived and appears recently updated. Repository commit activity is also currently absent over the last 3 months, so the package should not be adopted under this name without confirming the replacement package and its continuity.

Latest 2.2.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Registry deprecationdanger

Packagist marks this package as abandoned and specifies teqneers/shamir as the replacement. This is a severe maintenance and adoption risk for a new dependency under tq/shamir.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although a recent release or push is visible elsewhere, the lack of measured commit activity raises maintenance-continuity concerns.

Token permissionscaution

The workflow lacks top-level token permissions and relies on job-level permissions. No write permissions were detected, but explicit top-level least-privilege declarations would be clearer.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Stefan Gehrig
Oliver Müller

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^6.4.3 || ^7.0 || ^8.0
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform