Package Health

directorytree/opensearch-client

The package includes tests, a useful README, and release notes for this version. Organization backing and recent commits help, but workflow pinning and the single-contributor history merit monitoring.

Latest v1.0.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This is a young package, 96 days old, with only one release and no established release cadence. That limits evidence of long-term maintenance but does not by itself indicate abandonment.

Repo bus factorcaution

One contributor made all 6 commits in the last 3 months, creating a thin maintenance base and elevated continuity risk. Organization backing partly compensates because maintenance can potentially be handed off.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap for a dependency published to a registry.

Security policycaution

The repository has no security policy. This is a maintenance and disclosure-process gap, though it is not evidence that the release is unsafe.

Workflow auditcaution

Both workflows were analyzed with no audit findings or untrusted-trigger sinks, but all 5 action references are unpinned and one workflow grants top-level write permissions. These are workflow hygiene concerns rather than severe risks here.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Steve Bauman

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.0
—
—
illuminate/support
Version ^11.0|^12.0|^13.0
—
—
opensearch-project/opensearch-php
Version ^2.6
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform