Package Health

wikimedia/zest-css

Fast, lightweight, extensible CSS selector engine for PHP

Latest 4.1.2PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

85

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Name lookalikecaution

The name resembles wikimedia/less.php and the indicator says it borrows that lookalike identity, which warrants caution. However, artifact overlap is 0.0 and the README does not identify the package as the lookalike, so this is not strong copy evidence.

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the registry shows two releases in the last 12 months and the repository was pushed recently.

Repo popularitycaution

The repository has only 4 stars and 2 forks, providing limited community adoption evidence. Popularity is supporting evidence, so this lowers confidence in external support without determining health.

Repo toolingcaution

Composer is used for builds, which fits the package ecosystem, but no security scanning tooling was detected. The missing scanning process is a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy. For a reusable selector library this leaves vulnerability-reporting expectations unclear, though it is not evidence of a vulnerability by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christopher Jeffrey
C. Scott Ananian

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform