Package Health

ez-php/graphql

It includes a clear README, tests, and a small runtime dependency set. The repository is active and backed by an organization, but its single-contributor history and unpinned workflow actions reduce confidence.

Latest 2.5.6PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo bus factorcaution

One contributor made 100% of the 80 commits in the last three months. Organization backing provides some handoff capacity, but no second active contributor is visible, leaving a real continuity risk.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.

Workflow auditcaution

The workflow audit completed cleanly with no untrusted checkouts, script injection, or high-confidence findings, and it scopes permissions at job level. All 8 action references are unpinned, so the workflow is exposed to avoidable action-drift risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andreas Uretschnig

Direct Dependencies

DependencyLast ReleaseScore
ez-php/http
Version ^2.0
—
—
ez-php/contracts
Version ^2.0
—
—
ez-php/dataloader
Version ^2.0
—
—
webonyx/graphql-php
Version ^15.0
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform