Package Health

evansims/openfga-mcp

Release documentation and repository security controls are solid, with no install-time script. The available maintenance evidence does not support relying on this release for ongoing fixes or updates.

Latest v2.0.0PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning that new consumers should not expect supported development.

Repo commit activitydanger

The repository had zero commits and zero active maintainers in the last 3 months, reinforcing the archived project's lack of ongoing maintenance.

Repository archiveddanger

The linked repository is archived, and its last push was about 10 months ago. Archiving strongly indicates that the project is no longer maintained.

Release historycaution

Only two releases exist, with the latest released about 13 months ago and no releases in the last 12 months. The short release history and prolonged silence increase abandonment risk.

Workflow auditcaution

All 13 workflows were analyzed, use read-only permissions, and pin all 77 analyzed action references. The auditor also reported high-confidence template-injection findings in three security workflows; these are workflow hygiene concerns rather than a dependency-health verdict on their own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Evan Sims

Direct Dependencies

DependencyLast ReleaseScore
php-mcp/server
Version ^3.2
—
—
guzzlehttp/guzzle
Version ^7.2
—
—
evansims/openfga-php
Version ^1.5
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform