Package Health

logbrew/sdk

This is a well-supported, actively developed release with 20 releases in 89 days, a recent repository push, substantial commit and pull-request activity, an organization-owned and package-matching repository, clear MIT licensing, tests, a substantial README, minimal runtime dependencies, and no install-time scripts or dangerous workflow patterns. The main concerns are that the package is still pre-1.0, all 803 recent commits came from one contributor despite organizational ownership, the repository has no security policy, and one workflow grants top-level write permissions; these merit review but do not outweigh the strong maintenance and transparency evidence.

Latest v0.1.19PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All 803 recent commits were made by one contributor, creating a genuine continuity and bus-factor concern. Organization ownership provides some ability to hand maintenance off, but no second active contributor is shown.

Repo toolingcaution

Composer is used as a build tool, supporting reproducible package-oriented development, but no security-scanning tools were detected, leaving a security-process gap.

Security policycaution

The repository has no security policy, reducing transparency around vulnerability reporting and response expectations.

Token permissionscaution

Five workflows use read-only permissions and none lack a top-level declaration; one publishing workflow has top-level write permissions, which is understandable for release automation but increases the impact of a workflow compromise.

Version stabilitycaution

The assessed version v0.1.19 is not a prerelease, but the package remains below major version 1, so API stability and long-term maturity are less established.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform