Package Health

z38/murmurhash

The README, tests, matching repository, and MIT license provide useful transparency for this small library. Its lone maintainer and minimal adoption offer little evidence of ongoing support, so pinning this old release carries maintenance risk.

Latest v0.1.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historydanger

The package has only one release, published nearly 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the package remaining non-deprecated.

Repo commit activitydanger

The repository has had zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no update since 2016. There is no observed recent maintenance capacity.

Maintainerscaution

One registry publishing maintainer is listed, providing a thin support base. The linked repository is user-owned rather than organization-backed, so no broader backing is shown to compensate.

Repo popularitycaution

The repository has only 2 stars, 3 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little community support to offset the lack of activity.

Repo toolingcaution

Composer is used as the build tool, which fits the ecosystem and supports reproducible project setup. No security scanning tool is present, but this is a secondary hygiene gap for this small, inactive package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

z38

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform