Package Health

chubbyphp/chubbyphp-negotiation

This is a mature, actively published package with a stable major version, a recent release, a correctly matching repository, documented source structure, repository tests, build tooling, and security scanning. The main concerns are the very small recent contributor base, limited repository activity, absence of a security policy, and unspecified workflow token permissions; these warrant review but do not outweigh the package's long release history, current repository state, organization backing, and lack of deprecation or dangerous workflow patterns.

Latest 2.3.4PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All 2 recent commits came from one contributor, creating a concentrated bus factor. The organization-owned project backing partly mitigates handoff risk, so this remains a caution rather than a danger.

Repo commit activitycaution

Only 2 commits from 1 active maintainer were recorded in the last 3 months. Recent release activity compensates for the possibility of abandonment, but the low current commit volume still indicates limited ongoing development capacity.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. The clean queue is positive, but the lack of observed collaboration provides little evidence of a broad maintenance community.

Repo popularitycaution

The repository has only 2 stars, 2 forks, and 1 watcher, indicating a small user and contributor footprint. Popularity is supporting evidence rather than a verdict, so this is a modest caution rather than a severe health concern.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though security scanning is present in repo_tooling.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dominik Zogg

Direct Dependencies

DependencyLast ReleaseScore
psr/http-message
Version ^1.1|^2.0

Weekly Downloads

Info

Last Published
14 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform