Package Health

xds/composer-framework

The codebase is small, has one runtime dependency, and uses no install-time scripts. The minimal README and absent security policy reduce transparency, while the project shows little evidence of ongoing care.

Latest v1.0.3PackagistPackagist

42%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

57

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has had no release in nearly four years, with four releases clustered on 13 June 2022 and none in the last 12 months. This is strong evidence of abandonment risk.

Package scaffoldingcaution

The package includes a README and release notes for this exact version, which provides some consumer and release transparency, but the README is only 7 characters and offers little integration guidance.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these numbers provide no meaningful external maintenance signal.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools are present. The missing scanning is a modest transparency and maintenance gap.

Repository archivedcaution

The linked repository is not archived, but its last push was in June 2022, consistent with the older release history and limited maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

xds

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform