Package Health

junipeer/apiclient

Risky to adopt: this stable library has had no release or repository activity for nearly six years. The missing README and absent security policy add transparency concerns, although it is not deprecated or archived and has a clear Apache-2.0 license.

Latest 1.0.0PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has only one release, published nearly six years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a library dependency.

Repo commit activitydanger

The repository has had zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.

Package scaffoldingcaution

The published library has no README, which makes integration and usage harder for consumers; absent tests and changelog files are normal packaging practice and do not add concern here.

Repo popularitycaution

The repository has zero stars, forks, and watchers, providing no supporting evidence of community use or review. Popularity is only supporting evidence, so this reinforces rather than determines the maintenance concern.

Security policycaution

The repository has no security policy, so there is no documented process for reporting vulnerabilities or handling security issues. This is a transparency gap, but not by itself evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ~5.3.1||~6.0||~7.0
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform