Package Health

imiphp/imi-swoole-tracker

The package has a clear README, organization backing, and no install-time scripts. Its license signals disagree, there is no security policy or scanning, and the workflow uses an unpinned action.

Latest v2.1.9PackagistPackagist

53%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Licensecaution

The package declares MulanPSL-2.0 and has a license file, but the repository license file was detected as MIT. That mismatch should be clarified before adoption.

Release historycaution

The package has had no releases in the last 12 months, with the latest release on December 29, 2023. Its earlier median release interval of about 35 days shows prior activity, but the current pause raises maintenance concerns.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools were detected. This is a transparency and maintenance weakness, not evidence that the package is unsafe.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Workflow auditcaution

The sole workflow uses pull_request_target without an untrusted checkout or script injection, so the trigger is not concerning on its own. However, its one action reference is unpinned, creating a modest workflow reproducibility risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
imiphp/imi-swoole
Version ~2.1.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform