https://github.com/jackd248/composer-dependency-age
🕰️ A Composer plugin that analyzes the age of your project dependencies.
https://github.com/jackd248/composer-dependency-age
composer composer-plugin
Last synced: 11 months ago
JSON representation
🕰️ A Composer plugin that analyzes the age of your project dependencies.
- Host: GitHub
- URL: https://github.com/jackd248/composer-dependency-age
- Owner: jackd248
- Created: 2025-08-30T10:02:23.000Z (11 months ago)
- Default Branch: main
- Last Pushed: 2025-09-03T15:57:59.000Z (11 months ago)
- Last Synced: 2025-09-03T17:40:50.803Z (11 months ago)
- Topics: composer, composer-plugin
- Language: PHP
- Homepage:
- Size: 274 KB
- Stars: 0
- Watchers: 0
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- Contributing: CONTRIBUTING.md
Awesome Lists containing this project
README
# Composer Dependency Age
[](https://coveralls.io/github/jackd248/composer-dependency-age)
[](https://github.com/jackd248/composer-dependency-age/actions/workflows/cgl.yml)
[](https://github.com/jackd248/composer-dependency-age/actions/workflows/tests.yml)
[](https://packagist.org/packages/konradmichalik/composer-dependency-age)
A Composer plugin that analyzes the age of your project dependencies and provides neutral categorization to help you understand your dependency landscape. No risk assessment - just clear, objective information about when your dependencies were last released.
> [!warning]
> This package is in early development stage and may change significantly in the future. I am working steadily to release a stable version as soon as possible.
> [!note]
> Understanding the age of your dependencies is crucial for maintaining a healthy codebase.
> While newer isn't always better, knowing when your dependencies were last updated helps you make informed decisions about maintenance, security planning, and technical debt management.
> This tool provides objective age categorization without making assumptions about what you should do - empowering you to prioritize updates based on your project's specific needs, risk tolerance and maintenance windows.
## ✨ Features
- **Neutral Age Analysis** - Categorizes dependencies as Current, Medium, or Old based on release dates
- **Release Cycle Analysis** - Analyzes dependency activity patterns with 4-tier activity rating
- **Multiple Output Formats** - CLI table, JSON for automation, GitHub-formatted for PRs
- **Flexible Filtering** - Analyze all dependencies or focus on direct ones only
- **Smart Caching** - Caches Packagist API responses with configurable TTL for better performance
- **CI/CD Ready** - Perfect for automated dependency auditing in your build pipelines
- **Highly Configurable** - Customize thresholds, ignore lists, and output preferences
## 🔥 Installation
```bash
composer require konradmichalik/composer-dependency-age --dev
```
## 📊 Usage
### Command
Run the command to fully analyze your dependencies:
```bash
composer dependency-age
```
### Automatic Analysis
The plugin automatically runs after `composer install` and `composer update` operations, providing immediate feedback on your dependency landscape.
```shell
$ composer install
...
Dependency age ~ // 21.9 years in total (9 months average per package). Use composer dependency-age for full details.
...
```
## 📝 Configuration
### Command Line Options
| Option | Description | Default |
|--------|-------------|---------|
| `--format` | Output format: cli, json, github | cli |
| `--direct` | Show only direct dependencies | false |
| `--no-dev` | Exclude development dependencies | false |
| `--no-colors` | Disable color output | false |
| `--no-cache` | Disable caching | false |
| `--offline` | Use cached data only | false |
| `--ignore` | Comma-separated packages to ignore | - |
| `--thresholds` | Custom age thresholds (years) | current=0.5,medium=1.0,old=2.0 |
| `--no-release-cycles` | Disable release cycle analysis | false |
### Configuration via composer.json
```json
{
"extra": {
"dependency-age": {
"thresholds": {
"current": 0.5,
"medium": 1.0,
"old": 2.0
},
"ignore": ["psr/log", "psr/container"],
"output_format": "cli",
"include_dev": false,
"cache_ttl": 2592000,
"event_integration": true,
"event_operations": ["install", "update"],
"event_force_without_cache": false,
"enable_release_cycle_analysis": true,
"release_history_months": 24
}
}
}
```
## 📈 Age Categories
| Category | Sign | Timeframe | Description |
|----------|------|-----------|-------------|
| Current | ✓ | ≤ 6 months | Recently released dependencies |
| Medium | ~️ | ≤ 12 months | Moderately aged dependencies |
| Old | ! | > 12 months | Dependencies released over a year ago |
| Unknown | ? | - | Dependencies without release date information |
### Overall Project Rating
The overall rating in the summary is calculated based on the distribution of your dependencies:
| Rating | Symbol | Logic | Description |
|--------|-------|-------|-------------|
| **Mostly Current** | ✓ | ≥ 70% Current packages | Your project uses predominantly recent dependencies |
| **Needs Attention** | ! | ≥ 30% Old packages | Significant portion of dependencies are outdated |
| **Moderately Current** | ~️ | All other cases | Balanced mix of current and older dependencies |
## 🔄 Release Cycle Analysis
The plugin analyzes the release patterns of your dependencies to provide insights into their maintenance activity:
### Activity Categories
| Activity Level | Rating | Release Frequency | Description |
|----------------|--------|-------------------|-------------|
| **Very Active** | ●●● | ≤ 60 days | Highly active development with frequent releases |
| **Active** | ●●○ | ≤ 180 days | Regular maintenance with consistent releases |
| **Moderate** | ●○○ | ≤ 365 days | Periodic updates with moderate activity |
| **Slow/Inactive** | ○○○ | > 365 days | Infrequent releases or maintenance |
### Release Trend Detection
The analysis also detects release trends:
- **Accelerating** - Release frequency is increasing
- **Slowing** - Release frequency is decreasing
- **Stable** - Consistent release pattern
- **Unknown** - Insufficient data for trend analysis
### Configuration Options
- **`enable_release_cycle_analysis`** - Enable/disable release cycle analysis (default: `true`)
- **`release_history_months`** - Months of release history to analyze (default: `24`, range: 1-60)
- **`--no-release-cycles`** - Command line flag to disable analysis for faster execution
## 🧑💻 Contributing
Contributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) for guidelines.
## ⭐ License
This project is licensed under the GNU General Public License v3.0 - see the [LICENSE](LICENSE.md) file for details.