Package Health

alex-kalanis/restful

A clear README, release notes, and matching source tree make integration easier. The main concern is that this is a one-release project with no commits in the last three months, so expect limited maintenance.

Latest v1.0.0PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has only one release, published 631 days ago, with no releases in the last 12 months. That suggests limited evidence of ongoing maintenance, though the project is relatively young.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, consistent with the single-release history and indicating a meaningful maintenance risk.

Repo toolingcaution

The project uses Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a security-sensitive REST API library.

Workflow auditcaution

The only workflow has all 8 action references unpinned, which weakens build reproducibility. No untrusted checkouts, injection sinks, broad top-level write permissions, or auditor findings were detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Drahomír Hanák
Tomáš Vlczech Volf
Petr Kalanis Plšek

Direct Dependencies

DependencyLast ReleaseScore
nette/di
Version ~3.2
—
—
nette/http
Version ~3.3
—
—
nette/utils
Version ~4.0
—
—
tracy/tracy
Version ^2.10
—
—
nette/caching
Version ~3.3
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform