Package Health

byjg/rest-reference-architecture

Security scanning, tests, and a clear MIT license provide useful safeguards. The one-person maintenance base and repository mismatch make this release harder to trust long term.

Latest 6.1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo package mentiondanger

The linked repository is named php-gluo rather than byjg/rest-reference-architecture and its README does not mention this package. That mismatch raises concern that the repository may not be the package's actual source.

Project backingcaution

The repository is owned by a user account rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.

Repo bus factorcaution

One contributor made 100% of the 40 recent commits. This creates a significant continuity risk because no second active contributor is evidenced.

Repo commit activitycaution

The repository recorded 40 commits in the last 3 months, showing active work, but all activity came from one maintainer, limiting demonstrated maintenance breadth.

Workflow auditcaution

All three workflows were analyzed, but all 14 action references are unpinned and one workflow grants top-level write access. The only reported cache-poisoning issue is low confidence, so this is workflow hygiene rather than a severe finding.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
byjg/config
Version ^6.0
—
—
byjg/shortid
Version ^6.0
—
—
byjg/authuser
Version ^6.0
—
—
byjg/jinja-php
Version ^6.0
—
—
byjg/micro-orm
Version ^6.0
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform