Package Health

vergil-lai/lexsift-php

The package is well documented, licensed, and backed by a matching repository with tests and a controlled workflow. Its security policy is absent, so the project has less formal transparency while its maintenance record is still unproven.

Latest v0.1.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Project backingcaution

The package and repository are owned by the same individual account. That is consistent ownership, though it does not provide the resilience of organizational backing.

Release historycaution

This is the first release, published less than one hour before collection, so there is no release history to demonstrate sustained maintenance. Its very recent publication makes this an evidence gap rather than proof of abandonment.

Repo commit activitycaution

The repository has no commits or active maintainers in the past three months, so ongoing maintenance is not yet demonstrated. Because the package itself is newly published and the repository was pushed immediately beforehand, this is a maturity concern rather than severe abandonment evidence.

Repo toolingcaution

The project uses Composer, but no security scanning tooling was detected. The missing scanning automation is a modest hygiene gap, not evidence that the package is unsafe or unmaintained.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This lowers transparency slightly but does not by itself make the release unfit to use.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 hours ago
Created
5 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform