Package Health

chubbyphp/chubbyphp-swoole-request-handler

This is a mature, actively released package with a stable 1.6.7 version, seven releases in the last 12 months, a non-archived matching repository, repository tests, build and security tooling, and no registry deprecation or install-time lifecycle scripts. The main concerns are concentrated maintenance: all four commits in the last three months came from one contributor, and the repository lacks a security policy while its workflow does not declare top-level token permissions. These are meaningful transparency and continuity gaps, but the organization-owned repository, recent release activity, and existing test/tooling evidence make the package generally reasonable to depend on with normal review of updates.

Latest 1.6.7PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All four commits in the last three months came from one contributor, creating a real continuity and bus-factor concern. Organization ownership provides some handoff capacity, but no second recently active contributor is shown to compensate for the concentration.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and coordinated disclosure. This is a hygiene gap rather than evidence of unsafe code.

Token permissionscaution

The only workflow lacks top-level token permissions, so its effective permissions are not explicitly constrained at the workflow level. No top-level write permissions were detected, but the missing declaration remains a CI hardening gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dominik Zogg

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0|^3.0.2
psr/http-factory
Version ^1.1
psr/http-message
Version ^1.1|^2.0
dflydev/fig-cookies
Version ^3.2
psr/http-server-handler
Version ^1.0.2

Weekly Downloads

Info

Last Published
11 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform