Package Health

bluefission/simpleclients

Usable with caveats: the repository is active, tested, licensed, and backed by an organization, but this is a very young alpha release with all recent work concentrated in one contributor. Missing security policy and explicit workflow permissions add transparency and maintenance concerns.

Latest v0.1.1-alphaPackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historycaution

The package is only 39 days old with two releases, including a release roughly 14 days after the first; this shows some activity but provides little long-term maintenance evidence.

Repo bus factorcaution

One contributor made all 32 commits in the last three months, leaving no demonstrated handoff capacity if that contributor becomes unavailable; organization backing partly reduces this risk but does not remove it.

Repo popularitycaution

The repository has zero stars and forks and one watcher, so there is little external adoption evidence; this is supporting evidence only and does not outweigh the observed development activity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest gap in automated security hygiene.

Security policycaution

The repository has no security policy, making the preferred process for reporting vulnerabilities unclear.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Devon Scott

Direct Dependencies

DependencyLast ReleaseScore
bluefission/develation
Version ^1.3.39
—
—
simplehtmldom/simplehtmldom
Version ^2.0@RC
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform