Package Health

acdh-oeaw/arche-lib-ingest

This is a healthy, established release with a strong maintenance history: it has existed for over six years, has 74 releases, 8 releases in the last 12 months, a roughly 17-day median release interval, and a current stable version. The package is licensed, includes tests and a substantial source/test tree, is not deprecated or archived, and is backed by an organization-owned repository that matches the package. Recent repository activity is sparse and concentrated in one contributor, while the repository lacks security scanning, a security policy, and explicit workflow token permissions; these are meaningful hygiene concerns, but they do not outweigh the package's active release cadence, organizational backing, build/test setup, and direct repository alignment.

Latest 5.4.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitycaution

Only one commit from one active maintainer was recorded in the last 3 months, suggesting low recent development activity despite the much stronger release history.

Repo issue activitycaution

There is only one open issue and no issue or pull-request activity in the last month, which provides little evidence of active community engagement, though it does not indicate abandonment by itself.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, indicating limited external adoption; this is supporting evidence only and is outweighed by the package's release cadence and organizational backing.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected, leaving a repository security-hygiene gap.

Security policycaution

No repository security policy was found, reducing transparency around vulnerability reporting and response procedures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mateusz Żółtak

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7
—
—
kbsali/redmine-api
Version ^2.7
—
—
acdh-oeaw/arche-lib
Version ^7.6
—
—
zozlak/rdf-constants
Version ^1.2.1
—
—
acdh-oeaw/uri-normalizer
Version ^4
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform