Package Health

decole/planka-php-sdk

This release appears healthy and reasonable to depend on: it has a stable non-prerelease version, regular release activity over more than three years, a repository that is active and not archived, substantial documentation and tests, CI/build tooling, security scanning, and no registry deprecation or install-time scripts. The main concern is maintenance concentration: all 25 commits in the last three months came from one contributor, while the repository has no security policy and its workflows do not declare top-level token permissions. These are meaningful transparency and continuity gaps, but they do not outweigh the strong evidence of recent maintenance and package completeness.

Latest 2.1.1PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Project backingcaution

The repository is owned by a user account rather than an organization, so the single active contributor in the recent activity represents a genuine bus-factor concern rather than an organization-backed handoff model.

Repo bus factorcaution

All 25 commits in the last three months were made by one contributor, giving the project a concentrated maintenance base and increasing continuity risk if that contributor becomes unavailable.

Security policycaution

The repository has no security policy, which weakens vulnerability-reporting and disclosure transparency for a package that communicates with a remote API.

Token permissionscaution

Both workflows lack top-level GitHub Actions permissions declarations. Although no top-level write permissions were observed, explicitly restricting workflow token permissions would provide stronger supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Galochkin Sergey
Airy

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1|^2.0|^3.0
symfony/mime
Version ^6.4|^7.0
psr/http-client
Version ^1.0
psr/http-factory
Version ^1.0
fp4php/functional
Version ^6.0

Weekly Downloads

Info

Last Published
10 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform