Package Health

cleatsquad/php-http-replay

This release appears usable and reasonably well maintained, with strong package and repository hygiene: it has an MIT license, documentation, tests, changelog, a complete-looking source tree, no install-time scripts, a non-deprecated stable version, active recent commits, a security policy, read-only workflow permissions, and a repository that clearly matches the package. The main reservations are maturity and continuity: the project is only 22 days old, its eight releases were issued in very rapid succession, all 18 recent commits came from one contributor, and the repository has no recorded stars or forks. Those concerns warrant monitoring and make this less established than a mature dependency, but they do not indicate abandonment or make the release unfit to adopt.

Latest v2.1.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

The package is only 22 days old with eight releases, and the median interval is about 17 minutes, indicating rapid early iteration and limited evidence of long-term stability.

Repo bus factorcaution

One contributor made all 18 commits in the last three months, creating a meaningful continuity risk. Organization ownership provides some potential handoff capacity, but no second active contributor is shown.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Given the package is only 22 days old, this is a maturity and external-adoption concern but not evidence of abandonment by itself.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected; the missing automated security scanning is a modest transparency and maintenance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mohamed El Mrabet

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^7.0 || ^8.0
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—
guzzlehttp/guzzle
Version ^7.0 || ^8.0
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform