Package Health

cleatsquad/php-llm-router

This release appears usable and well-scaffolded, with an MIT license, extensive documentation, tests, changelog, security policy, clean workflow analysis, and a repository that is active, unarchived, and correctly associated with the package. The main concerns are that the project is very young (23 days old), all 75 recent commits come from one contributor, repository popularity is currently zero, and one workflow grants top-level write permissions while no security-scanning tooling was detected. These factors create meaningful continuity and process risk, but they are not currently outweighed by abandonment or registry-health indicators: the package is not deprecated, v5.5.0 is a stable release, and recent release and merge activity is strong.

Latest v5.5.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access, which is a continuity concern; the organization-owned repository provides some backing, but it does not eliminate single-publisher risk.

Release historycaution

Thirteen releases in 23 days, with a median interval of about 13 hours, shows active delivery, although the short history limits evidence of long-term stability.

Repo bus factorcaution

One contributor made all 75 commits in the last three months, creating a pronounced bus-factor risk; organization ownership offers potential handoff capacity but no second active contributor is shown.

Repo popularitycaution

The repository has zero stars, forks, and watchers. For a package only 23 days old this is not an abandonment verdict, but it provides no independent adoption or community signal.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanner is a process gap, though the repository does include other security-related controls.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mohamed El Mrabet

Direct Dependencies

DependencyLast ReleaseScore
mcp/sdk
Version ^0.7.0
—
—
psr/log
Version ^3.0
—
—
psr/simple-cache
Version ^3.0
—
—
guzzlehttp/guzzle
Version ^7.8
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform