Package Health

andydefer/php-search

This release appears usable and actively maintained: it is not deprecated or archived, has had 39 releases in the last 12 months with the latest published recently, and the linked repository contains a substantial source tree, documentation, and tests even though tests are not packaged. The main risks are project immaturity, complete dependence on one active contributor, no security policy, and no adoption indicators; these warrant caution but are partly offset by recent commit activity, build and security tooling, package-repository alignment, and a clear MIT license.

Latest v0.2.45PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health checks

Maintainerscaution

Only one account has registry publish access. This is a genuine continuity risk for a young package, although repository activity shows that the same owner is actively maintaining it.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational maintenance redundancy to offset the concentrated maintainer base.

Repo bus factorcaution

One contributor made all 20 commits in the last 3 months, creating a low bus factor and meaningful abandonment-continuity risk for a user-owned project.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. This is neutral for a small package but provides little evidence of community engagement or external review.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This provides no external adoption or redundancy evidence, but low popularity alone is not evidence that the package is unsafe to depend on.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andy Kani

Direct Dependencies

DependencyLast ReleaseScore
andydefer/php-jsonl
Version ^0.11.8

Weekly Downloads

Info

Last Published
6 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform