Package Health

darvis/api-x

Documentation, tests, a license, and a small runtime dependency set make integration clearer. The project is less than a day old, and its workflow inherits secrets and uses an unpinned action.

Latest v1.3.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Project backingcaution

The repository is owned by an individual rather than an organization, so the single registry maintainer reflects a genuinely thin ownership base. The linked repository and package identity are consistent, partially reducing that concern.

Release historycaution

This release is part of a package published less than a day ago, with four releases in that period. The rapid initial releases show activity but provide no meaningful long-term maintenance history.

Repo commit activitycaution

There were no commits or active maintainers in the preceding three months, but the repository was pushed less than an hour ago and the package itself is less than a day old. The short history limits confidence rather than proving abandonment.

Workflow auditcaution

The only workflow was fully analyzed and has no untrusted checkout or script-injection findings, but it inherits secrets with high-confidence medium severity and uses its only action without pinning. It lacks a top-level permissions block, which is acceptable on its own but provides less explicit permission control.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Arvid de Jong

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version ^11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
4 hours ago
Created
1 day ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform