It includes a substantial test suite, clear usage documentation, and a matching source repository. However, no repository commits were recorded in the last three months, while the project is still young and below version 1.0.
62%
Total Score
63
100
83
83
Only one registry publishing account is listed, which limits publishing redundancy. The repository is owned by the same individual, so this is a modest resilience concern rather than evidence of abandonment by itself.
The repository is owned by an individual rather than an organization, so there is no demonstrated organizational backing to compensate for the thin maintainer base.
No commits and no active maintainers were recorded over the last three months. This is concerning for a package whose entire history is only 92 days old, despite the recent registry release.
The repository has no stars, forks, or watchers. For a young, specialized package this is weak supporting evidence rather than a decisive health problem.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap, not a standalone reason to reject the release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
brick/date-time Version ^0.9.0 | — | — |
symfony/validator Version ^6.4|^7.4 | — | — |
ardenexal/fhir-path Version ^0.6.1 | — | — |
ardenexal/fhir-models Version ^0.6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.