Package Health

tualo/dav

The package has only a six-character README and no repository security policy or security-scanning tool. Its MIT licensing, small dependency set, and organization-backed repository provide useful transparency, but ongoing quality and security practices are limited.

Latest 1.0.2PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package scaffoldingcaution

The artifact includes a README, but it is only six characters long and offers essentially no consumer guidance. The absence of tests and a changelog is expected packaging practice and is not itself a gap.

Release historycaution

Only two releases have been published over about 15 months, with one release in the last 12 months; this provides limited evidence of sustained maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful abandonment concern for a package still being depended on.

Repo toolingcaution

Composer is used for builds, but no repository security-scanning tool was detected, leaving security-quality checks less transparent.

Security policycaution

The linked repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Thomas Hoffmann

Direct Dependencies

DependencyLast ReleaseScore
sabre/dav
Version 4.7.0
—
—
ramsey/uuid
Version ~4.9.0
—
—

Weekly Downloads

Info

Last Published
11 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform