Package Health

guzzlehttp/command

The package includes consumer documentation, repository tests, release notes, and a clear license. Organization backing and read-only workflow permissions help offset concentrated development and unpinned automation references.

Latest 2.0.1PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo bus factorcaution

One contributor holds 100% of the recent commit share. Organization ownership provides some handoff capacity, but no second recently active contributor is shown, so the concentration remains a maintenance concern.

Repo commit activitycaution

The repository recorded 23 commits in the last 3 months, showing active work. However, all recent commits came from one active maintainer, which leaves maintenance capacity concentrated.

Workflow auditcaution

Both workflows were analyzed successfully, use read-only permissions, and have no reported high-confidence findings or untrusted execution paths. All 10 action references are unpinned, however, which leaves automation more exposed to upstream action changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Graham Campbell
Michael Dowling
Jeremy Lindblom
Tobias Nyholm

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^3.1
psr/http-client
Version ^1.0
guzzlehttp/guzzle
Version ^8.1
guzzlehttp/promises
Version ^3.0.2
symfony/polyfill-php80
Version ^1.25

Weekly Downloads

Info

Last Published
27 days ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform