Package Health

esi/api

The repository is small and all recent commits come from one maintainer. Tests, release notes, a license, and security tooling provide useful safeguards, but workflow dependency pinning is weak.

Latest v1.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

Only two releases exist, with none in the last 12 months; the latest release is from May 2024, which raises freshness and maintenance concerns despite recent repository activity.

Repo bus factorcaution

All recent commits came from one contributor, leaving maintenance dependent on a single person; the repository is user-owned, so there is no organization backing to offset that concentration.

Repo commit activitycaution

The repository recorded two commits in the last three months, showing some ongoing activity, but the volume is modest for a library with no recent registry release.

Workflow auditcaution

All nine action references are unpinned, which weakens build reproducibility, and the audit found a high-confidence adhoc package installation; however, there are no high- or medium-severity findings and no untrusted checkout or script-injection sinks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eric Sizemore

Direct Dependencies

DependencyLast ReleaseScore
symfony/cache
Version ^7.0
—
—
guzzlehttp/guzzle
Version ^7.0
—
—
kevinrob/guzzle-cache-middleware
Version ^5.1
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform