Package Health

varuog/zfe-user

It has a clear BSD-3-Clause license, tests, and a source repository that matches the package. A single maintainer, one star, and no security policy provide little evidence of durable support.

Latest 1.0.0alpha2PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

Only two releases were published, both in June 2017, with none in the last 12 months despite the package being about nine years old. This is strong evidence of abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but that does not compensate for the absent recent activity.

Maintainerscaution

Only one registry account has publish access. The linked repository is user-owned rather than organization-backed, so there is little visible publishing redundancy.

Repo popularitycaution

The repository has one star, zero forks, and one watcher. Popularity is not decisive, but these numbers provide no supporting evidence of a broad maintenance community.

Repo toolingcaution

Composer is used as the build tool, but no security-scanning tool was detected. The build setup is present, while security automation is absent.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Gourav Sarkar

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version *
—
—
facebook/graph-sdk
Version ^5.5
—
—
doctrine/mongodb-odm
Version ^1.1
—
—
zendframework/zend-i18n
Version ^2.7
—
—
zendframework/zend-mail
Version ^2.8
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform