Package Health

avadaneidanut/sapphp

The package has a clear README, MIT licensing, and no install-time scripts, which make its contents understandable and its installation relatively predictable. Its pre-1.0 status and absent security policy leave limited support and assurance for a dependency.

Latest v0.1.1PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

Only two releases were published, both in April 2016, with no releases in the last 12 months. That long absence of release activity is strong evidence of abandonment for a dependency.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, while its last push was in September 2016. This indicates that maintenance has effectively stopped for about 10 years.

Repo toolingcaution

Composer is used for builds, which is appropriate, but no security scanning tools are configured. That is a modest assurance gap for a package with no recent maintenance.

Security policycaution

The repository has no security policy. This is a transparency and response-process gap, though it is less serious than the demonstrated maintenance inactivity.

Version stabilitycaution

The latest version is v0.1.1 and the package has not reached a stable major release. This increases compatibility uncertainty, although the main concern is the much longer lack of maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Avadanei Danut

Direct Dependencies

DependencyLast ReleaseScore
psy/psysh
Version ^0.7.2
—
—
sabre/xml
Version ^1.4
—
—
illuminate/support
Version 5.2.*
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform