Package Health

yawave-sdks/yawave

The package includes a usable README, focused runtime dependencies, and an explicit GPL-2.0-or-later license. Its post-autoload-dump hook adds installation complexity, and the source repository could not be found for maintenance or provenance checks.

Latest 1.05PackagistPackagist

32%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was in October 2021, with no releases in the last 12 months despite about five years of package age. This is strong evidence of abandonment risk, although the 15-release history shows the project was previously active.

Lifecycle scriptscaution

The package runs a post-autoload-dump lifecycle script during installation. This adds operational and supply-chain exposure beyond a passive library, so it warrants caution even without evidence of malicious behavior.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Yawave

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^9.5.17 || ^10.4.2

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform