Package Health

yasirijaz/gusto

The source matches the package, includes a license, and avoids install-time scripts. The single maintainer and absent security policy provide limited evidence of ongoing support.

Latest v1.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

One registry maintainer is a thin support base for a user-owned project. The matching repository ownership provides accountability but does not demonstrate ongoing capacity.

Release historycaution

There has been only one release, published about 3 years ago, with no releases in the last 12 months. That is a meaningful maintenance concern for a dependency, though the stable 1.0.0 version may be complete.

Repo commit activitycaution

The repository recorded no commits and had no active maintainers in the last 3 months, consistent with the last push being about 3 years ago. This is the strongest evidence of possible abandonment.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response. This matters more when maintenance activity is already absent.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

yasir

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.8
guzzlehttp/promises
Version ^2.0

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform