Package Health

yuga/framework

The package is clearly licensed, recently released, and has a documented security contact. Ongoing work is concentrated entirely in one contributor, while the repository reports no security-scanning tooling or tests, limiting confidence in long-term resilience.

Latest v5.2PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo bus factorcaution

All 19 recent commits came from one contributor, so maintenance depends entirely on a single person and has limited handoff resilience.

Repo toolingcaution

Composer is used for builds, but no security-scanning tools were detected, leaving a meaningful verification gap for a framework with database, authentication, and application functionality.

Workflow auditcaution

No GitHub Actions workflows were present, so there were no workflow hazards to flag; this also means the audit provides no evidence of automated CI or security checks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Hamidouh Semix

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0
—
—
tracy/tracy
Version ^2.12
—
—
opis/closure
Version ^3.6
—
—
yuga/runtime
Version ^1.0
—
—
symfony/finder
Version ^5.3
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform