Package Health

waglpz/webapp-meta

This release is usable but carries meaningful maturity and maintenance uncertainty. It is licensed, non-deprecated, linked to a matching repository, has a stable version, and has no install-time lifecycle scripts or dangerous workflows. However, the package is effectively brand new, with only two releases published within hours, no observed commits or active maintainers over the prior three months, no tests or changelog, no security scanning or security policy, and a relatively substantial runtime dependency surface. The repository was updated today, so the lack of historical activity may partly reflect its age, but there is not yet enough evidence of sustained maintenance to rate it as healthy for an important dependency.

Latest v3.1.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 20 runtime dependencies, including several PHP extensions and application libraries. This broad dependency surface increases transitive maintenance and compatibility exposure for a package whose own artifact is minimal.

Package file treecaution

The artifact and repository each contain only four files: .gitignore, LICENSE, README.md, and composer.json. This is consistent with a lightweight meta-package, but leaves little implementation, test, or documentation evidence to assess.

Package scaffoldingcaution

A README documents the intended meta-project usage and development tools, but neither the artifact nor repository contains tests or a changelog. For a configuration and dependency-sharing meta-package, missing packaged tests is less significant, but the absence of both tests and release documentation still limits maturity evidence.

Project backingcaution

The repository is owned by an individual user rather than an organization. Individual ownership is valid, but it provides less visible backing and bus-factor assurance than organization ownership, especially for a package with no demonstrated activity history.

Release historycaution

Only two releases exist, both published within roughly one hour, and the package age is zero days. This is too little history to demonstrate sustained maintenance or release discipline.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
aura/sql
Version ^5.0
aidphp/http
Version dev-master
ramsey/uuid
Version ^4.9
aura/sqlquery
Version ^3.0
slim/php-view
Version ^3.4

Weekly Downloads

Info

Last Published
12 days ago
Created
12 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform