Package Health

zver/finder

Risky to adopt for new projects: this package has had no release or repository activity since June 2016. It has tests, documentation, a license, and no runtime dependencies, but its decade-long inactivity leaves maintenance and compatibility concerns.

Latest 1.0.0PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health checks

Release historydanger

The package has only one release, published about 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the package not being deprecated.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with the last push being about 10 years ago. This materially increases the risk that defects or compatibility problems will go unaddressed.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no observed organizational backing to compensate for the thin maintenance evidence.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, offering little community evidence or backup support. Popularity is supporting evidence rather than decisive on its own, but it provides no compensation for the stale release history.

Repo toolingcaution

Composer is used as a build tool, which supports reproducible project handling, but no security scanning tools are present. The missing scanning is a modest transparency gap rather than a standalone reason to reject the package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform