Package Health

yangweijie/think-runtime

The package has clear documentation, tests, a license, and a matching source repository. It lacks a security policy and automated security scanning, so future issues may be slower to detect.

Latest v1.3.4PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package is about 15 months old, but its latest registry release was over 15 months ago and it had no releases in the last 12 months. The five releases were clustered within about a day, leaving no evidence of ongoing release maintenance.

Lifecycle scriptscaution

The package declares a post-install command, so installation performs additional package-defined work beyond extracting files. That deserves review because install-time scripts increase dependency installation risk.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful abandonment concern, although the repository is not archived and the release includes supporting documentation and tests.

Repo issue activitycaution

There were two open issues and no issue or pull-request activity in the last month. This adds limited evidence of low ongoing project activity but is weaker than the lack of recent commits.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing security automation modestly reduces assurance for a package that handles application runtime infrastructure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

jay

Direct Dependencies

DependencyLast ReleaseScore
nyholm/psr7
Version ^1.3
—
—
psr/http-message
Version ^1.0|^2.0
—
—
nyholm/psr7-server
Version ^1.0
—
—
topthink/framework
Version ^8.0
—
—
topthink/think-orm
Version 3.*
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform