Package Health

zhuchunshu/codefec

The MIT license and matching repository make ownership and reuse clear. Install-time scripts and a large runtime dependency set add integration overhead.

Latest V1.2.2PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was published in August 2021, with no releases in the last 12 months. This is strong evidence of abandonment for a framework-style application package.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap and indicating no observable ongoing maintenance.

Dependency profilecaution

Nineteen runtime dependencies, including Laravel, Octane, Horizon, Telescope, and Workerman, create a broad compatibility surface and increase maintenance demands for an already inactive project.

Lifecycle scriptscaution

The package runs post-autoload-dump, post-create-project-cmd, and post-root-package-install scripts. These add install-time behavior that warrants care, though such scripts can be normal for a Laravel application.

Repo toolingcaution

Composer is used for builds, but no security-scanning tooling is present. This is a modest transparency and hygiene gap, not a severe risk by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
laravel/ui
Version ^3.2
mews/captcha
Version ^3.2
doctrine/dbal
Version ^3.0
mews/purifier
Version ^3.3
predis/predis
Version ^1.1

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform