Package Health

infinityloop-dev/graphpinator-parser

Parser subproject for GraPHPinator: GraphQL server implementation for PHP.

Latest v2.0PackagistPackagist

69%

Total Score

caution

Usable with caveats: maintenance activity has paused and all workflow actions are unpinned.

Health Score Breakdown

Maintainerscaution

Only one registry account has publishing access, which is a narrow publishing base. The repository is organization-owned, so this is partly compensated by project backing rather than treated as a severe risk.

Release historycaution

The package has six releases since March 2021 and one release in the last 12 months, with the latest published on December 16, 2025. This shows continued release activity but a modest cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. The recent release provides some evidence of maintenance, but the current pause raises abandonment and response-time concerns.

Workflow auditcaution

The only workflow was fully analyzed with no untrusted checkouts, injection findings, or high-confidence audit issues. However, all 11 action references are unpinned, weakening build reproducibility and making workflow dependencies harder to control.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Václav Pelíšek

Direct Dependencies

DependencyLast ReleaseScore
infinityloop-dev/utils
Version ^2.0
—
—
infinityloop-dev/graphpinator-common
Version ^2.0
—
—
infinityloop-dev/graphpinator-tokenizer
Version ^1.3
—
—

Weekly Downloads

Info

Last Published
9 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform