Package Health

coisa/service-provider

It includes repository tests, a matching source project, and a clear MIT license. All three workflow actions are unpinned, and no security policy is published.

Latest 2.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The latest release was published on December 30, 2021, nearly five years before collection, with no releases in the last 12 months. This substantially raises maintenance and abandonment risk despite seven historical releases.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the measured three-month period. That indicates little recent development activity, even though the repository is not archived.

Security policycaution

The repository has no published security policy. This is a transparency gap for a dependency, although the available workflow audit and security tooling provide some compensating hygiene evidence.

Workflow auditcaution

The workflow audit completed successfully with no dangerous triggers, injection findings, or high-severity issues. However, all three referenced actions are unpinned, leaving them exposed to upstream reference changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Felipe Sayão Lobato Abreu

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^1.0|^2.0
coisa/exceptions
Version ^1.0
container-interop/service-provider
Version ^0.4.0

Weekly Downloads

Info

Last Published
4 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform