Package Health

usox/harm

The stable version, MIT licensing, tests, and clear package match provide useful transparency. Those positives cannot offset the project’s abandoned and withdrawn status.

Latest v4.2.2PackagistPackagist

10%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

56

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement provided. This is a severe dependency risk because the package is explicitly withdrawn from active use.

Release historydanger

The package has 28 releases, but its latest release was over seven years ago and it had no releases in the last 12 months. The historical cadence does not compensate for the prolonged inactivity.

Repo commit activitydanger

There were no commits and no active maintainers in the past three months. Together with the archived repository, this confirms a lack of current maintenance.

Repository archiveddanger

The linked repository is archived, and its last push was over seven years ago. This strongly indicates that maintenance and issue resolution have ended.

Project backingcaution

The repository is owned by a personal user account rather than an organization, so there is no visible organizational maintenance buffer. This adds context to the inactivity but is not severe by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Jakob

Direct Dependencies

DependencyLast ReleaseScore
hhvm/hsl
Version ^4.0
—
—
facebook/hack-codegen
Version ^4.2
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform