Package Health

kaveraa/api-gouv-publique-fr

The project is only one day old, so its long-term maintenance record is unproven. Documentation, tests in the repository, licensing, security policy, and recent release work provide a solid foundation; pin this version while the project establishes a longer track record.

Latest v1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Project backingcaution

The registry namespace and repository are owned by the same individual account, which is consistent ownership but provides a narrow visible backing base for a new project.

Release historycaution

The package is only 1 day old, despite 5 releases in that period, so there is not yet enough history to judge sustained maintenance or release stability.

Repo commit activitycaution

The repository reports 0 commits and 0 active maintainers in the last 3 months, but the project is only 1 day old; this is mainly an unproven maintenance record rather than evidence of abandonment.

Workflow auditcaution

Both workflows were analyzed successfully with no audit findings or untrusted checkout and script-injection paths. However, all 12 action references are unpinned and one workflow grants top-level write permissions, creating a modest supply-chain and token-scope hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Augustin Kavera

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/simple-cache
Version ^2.0 || ^3.0
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform