Package Health

avanza-git/phpcas

Documentation and licensing are clear, and the repository still has tests and automated dependency scanning. The lack of recent commits and the project's stated search for maintainers make long-term fixes uncertain; pin this version if you adopt it.

Latest 2.0.0PackagistPackagist

51%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Licensecaution

The package declares Apache-2.0 and includes license files, but the artifact also detects BSD-3-Clause, which is not covered by the declaration. The release is licensed, though the licensing metadata is not fully aligned.

Package scaffoldingcaution

The artifact includes a README and this exact version has GitHub release notes; the source repository also has tests and a changelog. The README explicitly says the project is unmaintained and seeking active maintainers, which materially increases abandonment risk.

Release historycaution

The package has had no release in the last 12 months, and its latest release was about 14 months ago. This is a meaningful maintenance concern for an authentication library.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. That supports the project's statement that it is not actively maintained.

Security policycaution

The linked repository has no security policy. For an authentication library, the absence of a documented vulnerability-reporting process is a real transparency gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joachim Fritschi
Adam Franco
Henry Pan

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform