composer-concerto

v0.71.6

Concerto

Apache-2.0
Latest version published over 1 year ago
    npm install composer-concerto
  

Package Health Score

49 / 100
  • Popularity
    Limited
  • Maintenance
    Inactive
  • Security
    Security review needed
  • Community
    Sustainable

Popularity

Limited
Weekly Downloads (107)
Dependents
2
GitHub Stars
27
Forks
30
Contributors
95

The npm package composer-concerto receives a total of 107 downloads a week. As such, we scored composer-concerto popularity level to be Limited.

Based on project statistics from the GitHub repository for the npm package composer-concerto, we found that it has been starred 27 times, and that 2 other projects on the ecosystem are dependent on it.

Downloads are calculated as moving averages for a period of the last 12 months, excluding weekends and known missing data points.

Security

Security review needed

Security and license risk for recent versions


Direct Vulnerabilities

0.71.6-20190729145033
0.71.6-20190826174721
0.71.6-20190829021716
0.71.6-20190830190301
0.71.7-20190903160108
  • 0
    H
  • 0
    M
  • 0
    L
  • 0
    H
  • 0
    M
  • 0
    L
  • 0
    H
  • 0
    M
  • 0
    L
  • 0
    H
  • 0
    M
  • 0
    L
  • 0
    H
  • 0
    M
  • 0
    L

Indirect Vulnerabilities

0.71.6-20190729145033
0.71.6-20190826174721
0.71.6-20190829021716
0.71.6-20190830190301
0.71.7-20190903160108

License Risks

0.71.6-20190729145033
0.71.6-20190826174721
0.71.6-20190829021716
0.71.6-20190830190301
0.71.7-20190903160108
  • 0
    H
  • 0
    M
  • 0
    L
  • 0
    H
  • 0
    M
  • 0
    L
  • 0
    H
  • 0
    M
  • 0
    L
  • 0
    H
  • 0
    M
  • 0
    L
  • 0
    H
  • 0
    M
  • 0
    L

Security Policy
No
All security vulnerabilities belong to production dependencies of direct and indirect packages.

Snyk detected that the latest version of composer-concerto has a security vulnerability.

We highly advise you to review these security issues.

You can connect your project's repository to Snyk to stay up to date on security alerts and receive automatic fix pull requests.

We found a way for you to contribute to the project! Looks like composer-concerto is missing a security policy.

    # Install the Snyk CLI and test your project
npm i snyk && snyk test composer-concerto
Fix it in your project with Snyk!

Maintenance

Inactive
Commit Frequency
Open Issues
14
Merged PR
100
Open PR
0
Last Commit
1 month ago

Further analysis of the maintenance status of composer-concerto based on released npm versions cadence, the repository activity, and other data points determined that its maintenance is Inactive.

An important project maintenance signal to consider for composer-concerto is that it hasn't seen any new versions released to npm in the past 12 months, and could be considered as a discontinued project, or that which receives low attention from its maintainers.

In the past month we didn't find any pull request activity or change in issues status has been detected for the GitHub repository.

Community

Sustainable
Readme.md
Yes
Contributing.md
No
Code of Conduct
No
Contributors
95
Funding
No
License
Apache-2.0

With more than 10 contributors for the composer-concerto repository, this is possibly a sign for a growing and inviting community.

We found a way for you to contribute to the project! Looks like composer-concerto is missing a Code of Conduct.

Package

Node.js Compatibility
>=8

Age
2 years
Dependencies
11 Direct / 19 Total
Versions
4
Install Size
1.52 MB
Dist-tags
2
# of Files
102
Maintainers
2
TS Typings
No

We detected a total of 19 direct & transitive dependencies for composer-concerto. See the full dependency tree of composer-concerto

composer-concerto has more than a single and default latest tag published for the npm package. This means, there may be other tags available for this package, such as next to indicate future releases, or stable to indicate stable releases.