Package Health

voodoo-rocks/yii2-user

The MIT license and two runtime dependencies keep adoption straightforward. Missing consumer documentation and security practices add friction, while the repository’s minimal project structure offers little evidence of ongoing engineering.

Latest 0.2.0PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

Only two releases were published, both in April 2017, with no release in more than nine years. That is strong evidence of abandonment for a dependency receiving ongoing fixes.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving maintenance capacity un demonstrated.

Package scaffoldingcaution

The artifact has no README, which makes a library harder to integrate and understand. The absence of tests and a changelog is normal for published artifacts and is not counted against it.

Repo toolingcaution

Composer is used for builds, but no security scanning tool is configured. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.

Security policycaution

The linked repository has no security policy, leaving vulnerability reporting and response expectations unclear. Combined with the inactive project, this increases maintenance risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Voodoo Rocks Ltd.

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version ~2.0
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform