Package Health

zhangyi/utils

It has one publisher, no security policy, and declares a proprietary license, which limits transparency and adoption confidence. The repository is linked and the release is stable, but those positives do not offset the maintenance gap.

Latest v1.0.3PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published over three years ago, and there have been no releases in the last 12 months. Only three releases exist overall, indicating limited ongoing maintenance.

Repo commit activitydanger

The repository had no commits and no active maintainers in the last three months, consistent with the release history showing no activity for over three years.

Licensecaution

The package declares a proprietary license, so it is licensed, but the terms are less transparent and less suitable for an open-source dependency than a recognized open-source license.

Maintainerscaution

Only one registry account has publish access, leaving the package dependent on a single publisher. The repository is user-owned rather than organization-backed, so there is no shown maintainer redundancy.

Package scaffoldingcaution

A README is present and the stable release has a GitHub release record, which supports basic consumer documentation. The README is only 13 characters and no tests or changelog were detected, so transparency remains limited.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

张毅

Direct Dependencies

DependencyLast ReleaseScore
alibabacloud/dysmsapi-20170525
Version 2.0.20
—
—
tencentcloud/tencentcloud-sdk-php
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform