Package Health

get-stream/stream-chat

This is a mature, clearly licensed package with a substantial release history, stable versioning, current publication activity, tests, documentation, changelog, and a non-archived organization-backed repository. The main adoption concern is that the README explicitly places the package in maintenance mode and recommends the newer getstream-php package for new projects; recent repository activity is also very limited and concentrated in one contributor. It remains a usable dependency, but new projects should prefer the stated successor where feasible.

Latest 3.18.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a publishing continuity weakness, although the linked repository is owned by the GetStream organization and recent release activity demonstrates ongoing project backing.

Package scaffoldingcaution

The artifact and repository include a README, tests, and changelog, but the README explicitly states that stream-chat-php is in maintenance mode and recommends getstream-php for new projects. This is a meaningful lifecycle concern despite otherwise strong package hygiene.

Repo bus factorcaution

All one commit in the last three months came from a single contributor, creating a narrow recent contributor base. Organization ownership provides some ability to transfer maintenance, so this is a caution rather than a severe abandonment signal.

Repo commit activitycaution

Only one commit was recorded in the last three months, indicating very slow direct development activity. This is partly consistent with the package's stated maintenance mode but still raises concern about responsiveness to future changes.

Repo toolingcaution

The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning is a hygiene gap, though it is not decisive given the presence of CI and the separate security policy.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tommaso Barbugli

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^6.5.8 || ^7.0.1
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform