Package Health

duyler/openapi

This release appears healthy and reasonably safe to depend on: it is actively developed, has frequent releases, an unarchived and correctly linked repository, substantial source and test coverage in the repository, documented licensing and security policy, and automated build and security tooling. The main concerns are its relatively young age, pre-1.0 versioning, very concentrated recent commit activity (357 of 358 commits from one contributor), low repository popularity, and a workflow without top-level token permissions; these warrant monitoring but do not outweigh the strong maintenance and transparency evidence.

Latest 0.7.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a concentration concern. However, the repository is organization-owned and shows two active maintainers in recent commit activity, so registry access concentration is partly compensated by project backing.

Repo bus factorcaution

Recent activity is highly concentrated: one contributor made 357 of 358 commits, or about 99.7%, while the second made one. The organization backing provides some handoff capacity, but the observed concentration remains a genuine maintenance-continuity risk.

Repo popularitycaution

The repository has only 7 stars, 4 forks, and 3 watchers. Low popularity is supporting caution about external adoption and resilience, but it is not decisive because popularity alone does not establish package health.

Token permissionscaution

The only workflow lacks top-level token permissions, and no read-only or job-level permissions are declared. Although no write permissions are explicitly requested, the absence of an explicit restrictive policy is a workflow-hardening gap.

Version stabilitycaution

Version 0.7.2 is not a stable major release, so the API may still evolve before 1.0. However, it is not marked prerelease and recent releases have not used prerelease versions, which partly offsets the maturity concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mikhail Ilinsky

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
psr/cache
Version ^3.0
symfony/yaml
Version ^7.0 || ^8.0
psr/http-message
Version ^2.0
psr/event-dispatcher
Version ^1.0

Weekly Downloads

Info

Last Published
10 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform