Package Health

zoujingli/think-library

This release appears suitable to depend on: it has a long release history, recent publishing activity, stable versioning, an active non-archived source repository, a clear MIT license, tests, and no install-time lifecycle scripts. Maintenance is not especially broad—the repository made only 4 commits in the last 3 months and 75% came from one of 2 contributors—and the project lacks a security policy and security scanning, while its release workflow grants top-level write permissions. These are meaningful governance and bus-factor cautions, but they are outweighed by continued releases, recent repository activity, stable packaging, and the presence of tests.

Latest v6.1.98PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 12 runtime dependencies, including several PHP extensions and core framework components. This is a meaningful integration surface but not intrinsically unhealthy for a framework library.

Maintainerscaution

Only one registry account has publishing access, which is a modest release-account resilience concern. However, registry access records do not establish actual maintenance capacity, and repository activity shows two active contributors.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational handoff capacity to offset contributor concentration.

Repo bus factorcaution

Two contributors were active, but the top contributor made 75% of the recent commits. This concentration creates some continuity risk without indicating immediate abandonment.

Repo commit activitycaution

There were 4 commits in the last 3 months from 2 active maintainers, showing ongoing work but at a relatively modest pace for a core library.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Anyon

Direct Dependencies

DependencyLast ReleaseScore
symfony/process
Version ^5.4|^6.0|*
topthink/framework
Version ^6.0|^8.0|*
topthink/think-orm
Version ^2.0|^3.0
topthink/think-migration
Version ^3.0|*

Weekly Downloads

Info

Last Published
16 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform