Package Health

webflo/drush-shim

There has been no registry release for more than four years, with no commits or issue activity in the measured periods. The linked organization-backed project has a clear license and build setup, but a replacement is listed and continued maintenance is not evident.

Latest 0.10.0PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

30

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

The package is marked abandoned on Packagist at package scope, with drush/drush-launcher named as its replacement. This is a direct warning against adopting this release.

Release historydanger

The package has 34 releases since 2016, but none in the last 12 months and its latest registry release was in January 2022. The long release gap materially lowers confidence in continued maintenance.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months. This provides no evidence of ongoing maintenance.

Repository archiveddanger

The linked repository is archived, despite its last push being in August 2023. An archived source project is a severe abandonment risk for a dependency.

Repo issue activitycaution

There were no new or closed issues and no pull-request activity in the last month, while 22 issues remain open. This is consistent with a dormant project.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Florian Weber

Direct Dependencies

DependencyLast ReleaseScore
webmozart/path-util
Version ^2.3
—
—
webflo/drupal-finder
Version ^1.0
—
—
composer/xdebug-handler
Version ^1.0
—
—
laravel-zero/phar-updater
Version ^1.1
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform