Package Health

zetacomponents/cache

Tests, a changelog, a matching organization repository, and a stable Apache-2.0 license support predictable adoption. The lack of security scanning and a security policy leaves less assurance for future maintenance.

Latest 1.6.3PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has 26 releases since May 2012, but none in the last 12 months; its latest release was published nearly two years ago. This points to slowed maintenance, though the long release history shows maturity.

Repo commit activitycaution

The repository had 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since the latest release. This raises abandonment risk despite the repository remaining available.

Repo issue activitycaution

There were no new issues or merged pull requests in the last month, while 3 pull requests remain open. This provides little evidence of active current maintenance.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The build setup is useful, while the missing scanning reduces ongoing assurance.

Security policycaution

The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a maintenance and governance gap, not evidence of malicious behavior.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sergey Alexeev
Sebastian Bergmann
Jan Borsodi
Raymond Bosman
Frederik Holljen
Kore Nordmann
Derick Rethans
Vadym Savchuk
Tobias Schlitt
Alexandru Stanoi
Grady Kuhnline

Direct Dependencies

DependencyLast ReleaseScore
zetacomponents/base
Version ~1.8
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
20 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform