Package Health

aurigma/asset-processor-api-client

This is a usable but relatively young package with a stable non-prerelease version, a live organization-owned repository, recent publication activity, and a clear license file. The main concerns are limited maturity evidence: only three releases over 90 days, just two commits in the last three months by one contributor, no tests or changelog, no security policy or scanning tools, and negligible repository adoption. The generated-client structure and organization backing partly compensate for the documentation and contributor-base gaps, but the package should be adopted with ordinary dependency pinning and maintenance monitoring rather than treated as a mature, broadly validated dependency.

Latest 2.82.1.34176PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

A 2,464-character README documents installation, prerequisites, and usage, but the artifact and repository have neither tests nor a changelog. For an API client this is a genuine maintenance and transparency gap, though the usage documentation is useful compensation.

Release historycaution

The package is only 90 days old with three releases and a median release interval of about 45 days. This demonstrates ongoing publishing but provides limited evidence of long-term maintenance maturity.

Repo bus factorcaution

All two recent commits came from one contributor, creating a concentrated bus factor. Organization ownership provides some handoff capacity, but no second active contributor is evidenced.

Repo commit activitycaution

Only two commits were made in the last three months by one active maintainer. Recent activity exists, but the low volume limits confidence in sustained maintenance.

Repo popularitycaution

The repository has zero stars, forks, and watchers, so there is no external adoption evidence to support maturity. Popularity is only supporting evidence, but this still warrants some caution for a young package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aurigma Inc

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^1.7 || ^2.0
guzzlehttp/guzzle
Version ^7.3
jumbojett/openid-connect-php
Version ^0.9.2

Weekly Downloads

Info

Last Published
19 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform