Package Health

andrei-stepanov/soapclient-transports

Usable with caveats: the package has clear documentation, tests, a changelog, and an active-looking repository, but it has only one release and no commits in about four months. The missing security policy and unspecified workflow token permissions add transparency and maintenance concerns.

Latest 0.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health checks

Project backingcaution

The repository is user-owned rather than organization-backed, so the single registry maintainer reflects a narrow project base and leaves limited evidence of institutional continuity.

Release historycaution

This is the only release, published about 11 months after the first release date shown, so there is little observed release history to establish maturity or sustained maintenance.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a library intended for HTTP and SOAP integrations.

Token permissionscaution

The only workflow lacks top-level token permissions, so its GitHub Actions privileges are not explicitly constrained even though no write permissions were observed.

Version stabilitycaution

Version 0.1.0 is not a stable major release, indicating an early-stage API and greater compatibility risk for dependents.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andrei Stepanov

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
psr/http-message
Version ^2.0

Weekly Downloads

Info

Last Published
11 months ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform