Package Health

akeeba/json-backup-api

This release appears suitable to depend on: it is stable, licensed, non-deprecated, backed by an organization-owned repository, has a substantial README and test suite, and was released and pushed very recently. The main concerns are modest release frequency, very low repository popularity, complete concentration of recent commits in one contributor, and the absence of a repository security policy or security-scanning tooling. These are meaningful resilience and transparency gaps, but they are partly offset by current maintenance activity, organization backing, integration tests, and clean package structure without install-time scripts.

Latest 1.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historycaution

The package has existed for 1,188 days and has two releases in the last 12 months, including the assessed release, but only four releases overall and a median interval of about 261 days indicate a relatively deliberate release cadence.

Repo bus factorcaution

All three recent commits came from one contributor, giving a complete short-term commit concentration and creating continuity risk. Organization ownership provides some capacity to hand off maintenance, so this is caution rather than a severe failure.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher. Low popularity is supporting caution about external adoption and review, but it is not by itself evidence of abandonment for a specialized client library.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The build setup is appropriate, while the missing scanning capability is a modest transparency and defense-in-depth gap.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a genuine transparency gap for a library that handles remote API authentication and data operations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nicholas K. Dionysopoulos

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0.0|^3.0.0
—
—
psr/http-client
Version ^1.0.0
—
—
psr/http-factory
Version ^1.0.0
—
—
psr/http-message
Version >=1.0
—
—
composer/ca-bundle
Version ^1.3.0
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform