Package Health

contributte/openapi

Usable with caveats: the repository is active, tested, licensed, and recently released, but the project has only two releases and all recent commits come from one contributor. Review its small maintenance base before making it a critical dependency.

Latest v0.2.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historycaution

Only two releases exist across about 2 years and 8 months, with one release in the last 12 months. This is a thin release history, though the recent release shows the project is not abandoned.

Repo bus factorcaution

All 34 recent commits came from one contributor, leaving a concentrated maintenance base. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown.

Repo toolingcaution

The project uses Make and Composer, but no security-scanning tool was detected. This is a transparency gap rather than evidence that the package is unsafe.

Token permissionscaution

All four workflows omit top-level token permissions, so their default permissions are less explicit than desirable. No workflow requests top-level write access, which limits the concern.

Version stabilitycaution

Version 0.2.0 is not a stable major release, so the public API may still change; it is nevertheless a normal release rather than a prerelease.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Milan Felix Šulc

Direct Dependencies

DependencyLast ReleaseScore
nette/utils
Version ^4.0.0

Weekly Downloads

Info

Last Published
1 month ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform