Package Health

champs-libres/wopi-lib

Documentation and licensing are solid, with a clear package structure and automated analysis. Maintenance remains unproven after a single release, while workflow dependencies are broadly unpinned and include an archived action.

Latest v1.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package is 292 days old but has only one release, with no demonstrated release cadence beyond v1.0.0. This leaves ongoing maintenance and compatibility support uncertain.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. For a package with only one release, that makes continuing maintenance uncertain.

Security policycaution

The repository has no security policy. That is a transparency gap for a library implementing a protocol involving document access, even though automated scanning tools are present.

Workflow auditcaution

All 15 analyzed action references are unpinned, and the release workflow uses one archived action with high-confidence medium severity. Workflows were fully analyzed and showed no untrusted checkout or script-injection paths, limiting the risk to hygiene and maintenance concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/cache
Version ^1.0 || ^2.0 || ^3.0
—
—
loophp/psr17
Version ^1.0
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0.1
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—

Weekly Downloads

Info

Last Published
9 months ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform