Package Health

aurigma/storefront-api-client

This is a usable but relatively young package with a stable non-prerelease version, four releases over 90 days, a recent repository push, and organization backing from Aurigma. The main concerns are limited demonstrated maintenance depth—only three commits by one contributor in the last three months—along with no tests or changelog, no security policy, and no repository security scanning. These issues warrant caution for long-term dependency risk, but the unarchived repository, current release activity, license file, Composer tooling, and package-specific README provide meaningful compensating evidence.

Latest 2.68.1.34188PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The package has a substantial README, but it contains no packaged tests or changelog, and the repository also has neither. For an API client this weakens verification and change transparency, although the README documents installation, requirements, and usage.

Release historycaution

The package is only 90 days old with four releases and a median interval of about 28 days, showing recurring publication but limited long-term history. This supports current activity while leaving maturity and durability less established.

Repo bus factorcaution

One contributor made all three commits in the last three months, creating a concentrated bus factor. The organization-owned repository provides some handoff capacity, so this is a genuine resilience concern rather than a severe abandonment finding.

Repo commit activitycaution

The repository had three commits in the last three months, all from one active maintainer. This demonstrates recent maintenance but indicates a thin activity level for a package with an active release stream.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation but does not by itself indicate that the package is unsafe to depend on.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aurigma Inc

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^1.7 || ^2.0
guzzlehttp/guzzle
Version ^7.3
jumbojett/openid-connect-php
Version ^0.9.2

Weekly Downloads

Info

Last Published
17 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform