Package Health

digipolisgent/api-client

Three months without commits raises maintenance risk, and all five workflow actions are unpinned with high-confidence template-injection findings. Regular releases, tests, release notes, licensing, security policy, and organization backing provide meaningful counterweight.

Latest 4.2.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Lifecycle scriptscaution

A post-install-cmd script runs during installation. Its presence warrants some caution because install-time behavior affects consumers, although this signal does not show that the script is unsafe.

Repo commit activitycaution

The repository shows 0 commits and 0 active maintainers in the last 3 months, despite the recent release, leaving some uncertainty about ongoing development between releases.

Workflow auditcaution

All 5 action references are unpinned, and the audit found three high-confidence template-injection findings. The workflows have no untrusted checkout or dangerous trigger sink, so these are workflow hygiene concerns rather than a severe standalone dependency risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Peter Decuyper
Jelle Sebreghts
Lennart Van Vaerenbergh

Direct Dependencies

DependencyLast ReleaseScore
psr/http-message
Version ^1.0 || ^2.0
psr/simple-cache
Version ^1.0 || ^2.0 || ^3.0
guzzlehttp/guzzle
Version ^6.5 || ^7.0 || ^8.0
jumbojett/openid-connect-php
Version ^1

Weekly Downloads

Info

Last Published
3 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform