Package Health

aspose/words-sdk-php

Risky to adopt: this release is explicitly marked abandoned on Packagist and has a replacement package. The source repository is active and well-scaffolded, but recent work comes from one contributor, so migration to the replacement should be preferred.

Latest 26.9.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names aspose-cloud/aspose-words-cloud as its replacement. Although the current release is recent, depending on an abandoned package creates substantial continuity risk.

Repo bus factorcaution

One contributor made all 7 commits in the last 3 months, creating a concentrated maintenance dependency. Organization backing provides some handoff capacity, but no second active contributor is shown.

Repo commit activitycaution

The repository had 7 commits in the last 3 months, showing ongoing work. However, all recent activity came from one active maintainer, limiting the strength of that compensation.

Repo package mentioncaution

The repository name does not match the Packagist package name and its README does not mention that exact package name. A name mismatch can be normal for a subpackage, but the absent README reference leaves package-to-repository linkage less transparent.

Repo toolingcaution

Composer is used for builds, but no security-scanning tool is reported. The missing scanner is a transparency gap for supply-chain maintenance, though it is not evidence of maliciousness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aspose

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.13
—
—
phpseclib/phpseclib
Version ^3.0.55
—
—

Weekly Downloads

Info

Last Published
15 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform