Package Health

extport/grpc

This release appears generally suitable to depend on: it is a stable, non-deprecated version with regular releases over the past 88 days, an active non-archived repository, substantial source and test scaffolding, and a clear organization-backed mirror relationship to the upstream project. The main concerns are that all six recent commits came from one contributor, the repository has no detected security scanning or security policy, and several workflows use write permissions; these reduce transparency and operational resilience but do not outweigh the demonstrated release cadence and project structure.

Latest 1.84.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

One contributor made 100% of the six recent commits, creating a genuine continuity risk even though organization ownership may allow maintenance handoff.

Repo commit activitycaution

There were 6 commits in the last 3 months, showing ongoing activity, but only one active maintainer produced them; this is positive activity with limited demonstrated redundancy.

Repo issue activitycaution

There were no new or merged pull requests and no issue activity in the last month; this does not show abandonment by itself, but it provides little evidence of community maintenance or feedback handling.

Repo popularitycaution

The repository has zero stars, forks, and watchers. For a new automated mirror this is weak supporting evidence rather than a decisive health problem, especially given the release and scaffolding signals.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The build setup is therefore established while security-process transparency remains limited.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
14 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform