Package Health

hoels/app-store-server-library-php

This release appears usable and generally well maintained: it is a stable 2.3.0 release from a package with nearly three years of history, 19 releases, five releases in the last 12 months, a matching and actively pushed repository, tests, clear licensing, and no install-time scripts or deprecation status. The main adoption risks are concentrated maintenance capacity—only one active contributor and one commit in the last three months—and limited security transparency, with no security policy or security-scanning tools reported. The absence of a changelog and GitHub Actions is a smaller hygiene concern rather than evidence of abandonment, but the package should be monitored for maintainer continuity and upstream Apple API changes.

Latest 2.3.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

Eight runtime dependencies, including cryptographic, HTTP, and certificate-related libraries, create meaningful transitive maintenance exposure; the profile is not excessive for an App Store server API client but warrants dependency monitoring.

Maintainerscaution

Only one registry account has publish access. This is a genuine publishing continuity risk for a user-owned project, although repository activity provides some compensating evidence.

Project backingcaution

The repository owner is an individual user rather than an organization, so there is no organizational maintenance redundancy to offset the concentrated contributor base.

Repo bus factorcaution

All recent commits came from one contributor, giving the project a single-person bus factor and increasing continuity risk.

Repo commit activitycaution

Only one commit was recorded in the last three months from one active maintainer, showing that maintenance has slowed or is highly concentrated.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kai Hölscher

Direct Dependencies

DependencyLast ReleaseScore
hoels/ocsp-php
Version ^0.1
—
—
firebase/php-jwt
Version ^7.0
—
—
guzzlehttp/guzzle
Version ^7.8
—
—
phpseclib/phpseclib
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform