Package Health

yandod/candycane

The MIT license, included tests, release notes, and a repository that is not archived provide useful transparency. The project has no security policy or security scanning, leaving maintenance and response practices less clear.

Latest v0.9.6PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has had no release in nearly 11 years and no releases in the last 12 months, which is a substantial abandonment concern for an issue-tracking application.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months, indicating no current development activity despite the repository not being archived.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, while 26 issues and 13 pull requests remain open; this suggests limited ongoing maintenance.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are configured, leaving automated dependency or code-risk checks absent.

Security policycaution

The repository has no security policy, so users have no documented reporting or response process for security issues.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Yusuke Ando

Direct Dependencies

DependencyLast ReleaseScore
ensepar/tcpdf
Version 5.0.003

Weekly Downloads

Info

Last Published
10 years ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform