Package Health

aurigma/backoffice-api-client

This release appears usable and actively backed by an organization: it is not deprecated or archived, has a recent repository push, uses stable releases, includes a README and license file, and has no install-time lifecycle scripts or risky workflows. However, the package is relatively young at 90 days with only four releases, repository activity is light at three commits in the last three months and concentrated in one contributor, and there are no tests, changelog, security policy, or security-scanning tools. The generated-client structure and organizational ownership provide some context for the hygiene gaps, but the thin activity and single-contributor bus factor warrant caution before adopting it for a critical dependency.

Latest 2.68.1.34188PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

Seven runtime dependencies, including standard PHP extensions, Guzzle components, and an OpenID Connect client, represent a moderate dependency surface for an API client. The profile is not excessive, but each runtime dependency adds maintenance exposure.

Package scaffoldingcaution

A substantial README is present, but neither the artifact nor repository contains tests or a changelog. The documentation is useful for this API client, yet the missing validation and release-history documentation remain hygiene gaps.

Release historycaution

The package is young at 90 days and has only four releases, with a median interval of about 28 days. This shows ongoing publication but provides limited evidence of long-term maturity.

Repo bus factorcaution

All three recent commits came from one contributor, giving a complete concentration of activity in a single person. Organization ownership partly mitigates handoff risk, but no second active contributor is evidenced.

Repo commit activitycaution

Only three commits were made in the last three months by one active maintainer. Recent activity exists, but it is light and offers limited evidence of sustained maintenance capacity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aurigma Inc

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^1.7 || ^2.0
guzzlehttp/guzzle
Version ^7.3
jumbojett/openid-connect-php
Version ^0.9.2

Weekly Downloads

Info

Last Published
18 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform