Package Health

etolv2023/neo4j-php-client

The package has a clear MIT license, a substantial README, repository tests, and Psalm security tooling. Its short release history and no commits in the last three months leave maintenance capacity uncertain, while all 34 workflow actions are unpinned.

Latest v5.0.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package is only 142 days old with three releases and a median interval of about 4 days, so it shows initial activity but has not established a long maintenance record.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. Because the project is young and its latest release was about four months after collection's reference age, this is a meaningful maintenance concern.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity alone does not determine whether a small package is healthy.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Workflow auditcaution

All seven workflows were analyzed without dangerous triggers or audit findings, and none grant top-level write access. However, all 34 action references are unpinned, which weakens build reproducibility and supply-chain control.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ghlen Nagels

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
php-http/message
Version ^1.0
psr/http-factory
Version ^1.0
psr/http-message
Version ^1.0|^2.0
psr/simple-cache
Version ^2.0 || ^3.0

Weekly Downloads

Info

Last Published
4 months ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform