Package Health

weotch/phpthumb

The README and matching repository make the package easy to inspect. Maintenance has effectively stopped, with no recent commits or releases, and the repository has no security policy or scanning tools.

Latest 1.0.5PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was published in May 2015, with no releases in over 11 years and none in the last 12 months. This is strong evidence of abandonment for a dependency that may need ongoing compatibility fixes.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, while its last push was in May 2015. That confirms the long release gap reflects inactive development rather than a stable, recently maintained project.

Repo popularitycaution

The repository has 7 stars, 3 forks, and 1 watcher, providing little evidence of a broad active user or contributor base. Low popularity is supporting evidence rather than decisive on its own, but it does not compensate for the inactivity.

Repo toolingcaution

Composer is used for the build, which supports reproducible package management, but no security scanning tools are present. The missing scanning is a modest hygiene gap in an otherwise very small, inactive repository.

Security policycaution

The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance concern, though it is less severe than the prolonged inactivity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Robert Reinhard

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
11 years ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform