Package Health

gathercontent/client

This release appears suitable to depend on from a maintenance and transparency perspective: it is a stable major release, has recent release activity, is not deprecated or archived, includes a license, README, tests, and a conventional Composer build setup, and is backed by an organization-owned repository. The main concerns are that all three commits in the last three months came from one contributor, the repository has no security policy, and its GitHub Actions workflow does not declare top-level token permissions. Low popularity is only supporting context and does not outweigh the recent release and repository activity. Overall, the package is healthy but would benefit from a broader active maintainer base and stronger repository security hygiene.

Latest 1.2.2PackagistPackagist

80%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All three recent commits came from one contributor, creating concentration risk; organization ownership provides some capacity for handoff but does not remove the observed single-contributor exposure.

Repo popularitycaution

The repository has only one star and three forks, indicating limited public adoption; this is supporting context rather than a decisive concern because recent releases and organization backing are present.

Repo toolingcaution

Composer and Robo are used as build tools, supporting structured project maintenance, but no security scanning tools were detected.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.

Token permissionscaution

The only analyzed workflow lacks top-level token permissions, so its effective permissions are not explicitly minimized in the repository configuration.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.15.5
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform