Package Health

imbo/behat-api-extension

Documentation, licensing, release notes, and repository tests provide useful transparency, with organization backing. The single active contributor and four unpinned workflow actions are the main weaknesses.

Latest v6.1.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo bus factorcaution

One contributor made all four recent commits, creating a meaningful single-maintainer dependency risk. Organization backing provides some handoff capacity but does not remove the current concentration.

Repo commit activitycaution

Four commits occurred in the last three months, but all were made by one active maintainer; activity is present yet narrow.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving security checks less visible than the rest of the project hygiene.

Security policycaution

The repository has no security policy, which makes vulnerability reporting and response expectations less transparent.

Workflow auditcaution

The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all four action references are unpinned, so their versions can change without a repository change.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christer Edvartsen
Contributors

Direct Dependencies

DependencyLast ReleaseScore
behat/behat
Version ^3
—
—
beberlei/assert
Version ^3
—
—
firebase/php-jwt
Version ^7
—
—
guzzlehttp/guzzle
Version ^8.0
—
—
jimtools/basic-auth
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform