Package Health

aurigma/asset-generator-api-client

This release appears usable and reasonably maintained, with a stable non-prerelease version, three releases over the past 90 days, a non-archived repository updated on the assessment date, and organization backing from Aurigma. The main concerns are limited demonstrated maintenance depth—only two commits from one contributor in the past three months—along with no repository tests, changelog, security policy, or security-scanning tools. The package is licensed through both its manifest and License.md, but its proprietary license should be reviewed for compatibility before adoption.

Latest 1.37.1.34181PackagistPackagist

73%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package has seven runtime dependencies, including PHP extensions, Guzzle, and an OpenID Connect library. This is a meaningful dependency surface for an API client, but not inherently excessive for its stated functionality.

Package scaffoldingcaution

A substantive README is present, but the artifact and repository contain no tests or changelog. For an API client this is a genuine transparency and maintainability gap, though the documentation does explain prerequisites and usage.

Release historycaution

The package is only 90 days old with three releases and a median interval of about 45 days, showing ongoing publication but limited historical maturity.

Repo bus factorcaution

All two recent commits came from one contributor, creating concentration risk. Because the repository is organization-owned, handoff capacity partly compensates, but no second active contributor is evidenced.

Repo commit activitycaution

The repository received two commits in the past three months from one active maintainer, demonstrating recent maintenance but at a low cadence and with limited capacity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aurigma Inc

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^1.7 || ^2.0
guzzlehttp/guzzle
Version ^7.3
jumbojett/openid-connect-php
Version ^0.9.2

Weekly Downloads

Info

Last Published
19 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform