Package Health

tualo/osrm

The project has only two releases and no commits in the last three months, while its README is just 13 characters. MIT licensing, organization backing, a matching repository, and no install-time scripts provide useful safeguards.

Latest 1.0.2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Package scaffoldingcaution

The artifact includes a README, but it is only 13 characters and provides almost no consumer guidance. Missing tests and changelog files are expected packaging gaps here, not negative evidence.

Release historycaution

The package has only 2 releases over 444 days, with 1 release in the last 12 months and a median interval of about 118 days. This is limited maturity evidence, though the package is not abandoned solely on release count.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last three months. Combined with the sparse release history, this weakens evidence of continuing maintenance.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these counts provide little external validation.

Repo toolingcaution

The repository uses Composer build tooling, but no security scanning tools are present. The missing scanning is a hygiene gap rather than a severe dependency risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Thomas Hoffmann

Direct Dependencies

DependencyLast ReleaseScore
phpseclib/phpseclib
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
11 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform