Package Health

tuta/cartpoint

MIT licensing, included tests, and a repository that matches the package make the code easier to inspect. Its small dependency set and lack of install-time scripts reduce integration friction, but they do not offset the maintenance concern.

Latest v1.1.1PackagistPackagist

34%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has only one release, published about 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a framework integration package.

Repo commit activitydanger

There were no commits or active maintainers in the last 3 months, consistent with the repository's last push being about 10 years ago. This materially increases abandonment risk.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these counters provide no meaningful community-maintenance buffer.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools were detected. That is a modest hygiene gap rather than evidence the package is unsafe.

Security policycaution

The repository has no security policy. For a package with no recent maintenance, this further weakens transparency and vulnerability-reporting expectations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Irfan Mahfudz Guntur

Direct Dependencies

DependencyLast ReleaseScore
illuminate/events
Version 5.1.*|5.2.*
—
—
illuminate/session
Version 5.1.*|5.2.*
—
—
illuminate/support
Version 5.1.*|5.2.*
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform