Package Health

comfino/php-api-client

This release appears generally suitable to depend on: it is a stable, non-deprecated 3.3.0 release with nine releases in 148 days, a substantial documented codebase, tests, changelog, CI workflows, a license, and organization backing from Comfino. The main concerns are that repository commit activity reports no commits or active maintainers in the last 3 months despite the recent release, and the repository lacks a security policy and explicit top-level GitHub Actions token permissions. These are meaningful transparency and maintenance-process gaps, but they do not outweigh the strong release, scaffolding, licensing, and repository-alignment evidence.

Latest 3.3.0PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitycaution

The repository reports zero commits and zero active maintainers over the last 3 months, which is a maintenance concern; the very recent release and push provide some counter-evidence but do not fully resolve the mismatch.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected, leaving a modest security-process gap.

Security policycaution

No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.

Token permissionscaution

All three workflows lack top-level token permissions declarations. No workflow requests top-level write access, but explicit least-privilege configuration is still absent.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Artur Kozubski

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
psr/http-factory
Version ^1.1
psr/http-message
Version ^1.1 || ^2.0

Weekly Downloads

Info

Last Published
7 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform