Package Health

ufo-tech/component-transport-contracts

Usable with caveats: this is a clearly licensed, tested package from an organization-backed repository with a matching README and no deprecation or install scripts. It is brand new with only one release and no observed commits or issue activity yet, so long-term maintenance is unproven.

Latest 1.0.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health checks

Release historycaution

This is a new package released only once, with a package age of 0 days, so there is not yet enough history to demonstrate sustained maintenance.

Repo commit activitycaution

The repository records zero commits and zero active maintainers over the last three months. Because the package was released today, this may reflect its age, but it leaves ongoing maintenance unproven.

Repo issue activitycaution

There are no issues or pull requests and no recent issue or merge activity. For a repository released today this is limited evidence, but it provides no demonstrated community or maintenance activity yet.

Repo toolingcaution

Composer and Make tooling are present, but no security-scanning tools were detected. That is a modest transparency gap rather than a severe risk, especially for this small component.

Security policycaution

No repository security policy was found, reducing guidance for reporting and handling vulnerabilities, though this does not by itself indicate unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alex Maistrenko

Direct Dependencies

DependencyLast ReleaseScore
symfony/messenger
Version ^7.2

Weekly Downloads

Info

Last Published
1 hour ago
Created
1 hour ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform