Package Health

allegro-php/allegro

The MIT license, focused README, and matching organization-owned repository make adoption straightforward. A single published maintainer, no security policy, and no security scanning leave limited evidence of ongoing support.

Latest 0.2.0PackagistPackagist

53%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitydanger

There were no commits and no active maintainers in the last three months, while the last repository push was in December 2023. This strongly raises abandonment risk.

Dependency profilecaution

Seven runtime requirements, including PHP FFI and several FFI-related packages, create a relatively specialized integration surface. The profile is understandable for native-library bindings but may make adoption and maintenance more fragile.

Release historycaution

The package has four releases, but its latest release was in December 2023 and it had no releases in the last 12 months. That is meaningful evidence of slowed maintenance.

Repo toolingcaution

Composer is used as a build tool, which is appropriate for the package. However, no security scanning tools were detected, leaving a modest repository-hygiene gap.

Security policycaution

The repository has no security policy, so there is no documented route for reporting vulnerabilities or describing security handling.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dmitrii Polishchuk

Direct Dependencies

DependencyLast ReleaseScore
ffi/proxy
Version ^1.0
—
—
ffi/location
Version ^1.0
—
—
ffi/preprocessor
Version ^0.2.2
—
—
psr/simple-cache
Version ^3.0
—
—
ffi-headers/contracts
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform