Package Health

los/los-api-client

The MIT license, README, and comprehensive tests make the package easier to evaluate and integrate. Its security documentation is thin, and ongoing maintenance depends on one contributor.

Latest 1.0.3PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest registry release was published nearly eleven years ago, with only four releases and none in the past year. This is strong evidence of a dormant release line despite the repository being recently updated.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor findings are not visibly backed by a larger project structure.

Repo bus factorcaution

All recent commits came from one contributor, giving the repository a complete single-contributor concentration. The linked owner is an individual rather than an organization, so there is no provided backing signal to compensate for that concentration.

Repo commit activitycaution

Only one commit was recorded in the past three months, with one active maintainer. This indicates very limited current maintenance capacity.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap rather than a severe risk on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leandro Silva

Direct Dependencies

DependencyLast ReleaseScore
nocarrier/hal
Version ~0.9
—
—
zendframework/zend-http
Version ~2.4
—
—
zendframework/zend-modulemanager
Version ~2.5
—
—
zendframework/zend-servicemanager
Version ~2.5
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform