Package Health

xdli/q_and_a

The package is small, clearly licensed, and its README explains installation and API use. It has no security policy or automated security tooling, leaving maintenance and disclosure practices unclear.

Latest 1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has had only two releases, with the latest published over seven years ago and none in the last 12 months. This is strong evidence that the release is no longer actively maintained.

Repo issue activitycaution

There have been no new or closed issues or pull requests in the last month, alongside two open issues and no pull requests. This supports the conclusion that project maintenance is inactive.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling is reported. That leaves security hygiene less verifiable, though it is less serious than the maintenance gap.

Repository archivedcaution

The repository is not archived, which avoids the strongest abandonment indicator, but its last push was in January 2019 and does not offset the long period without releases.

Security policycaution

The repository has no security policy, so users are given no documented process for reporting vulnerabilities or receiving security guidance. This is a secondary transparency gap for a package that exposes application APIs.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

xdli 黎贤东

Direct Dependencies

DependencyLast ReleaseScore
encore/laravel-admin
Version ~1.6
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform