Package Health

madewithlove/htaccess-api-client

The package includes tests, a clear README, release notes, a license, and a small runtime dependency set. Its organization backing and recent repository activity are reassuring, though maintenance is concentrated and workflow references are not pinned.

Latest v3.0.0PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo bus factorcaution

All one commit in the last three months came from a single contributor, so observed maintenance is concentrated. The organization-owned project provides some capacity for handoff, but the current activity still leaves a thin operational base.

Repo commit activitycaution

One commit from one active maintainer in the last three months shows some recent maintenance, but the activity level is light. The recent release and organizational backing partly offset the limited cadence.

Security policycaution

No repository security policy was found. This is a transparency gap for reporting vulnerabilities, but it is not by itself evidence of abandonment or unsafe code.

Workflow auditcaution

Both workflows were analyzed successfully and had no reported audit findings or untrusted checkouts; the pull_request_target trigger is not dangerous on its own. However, all 9 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform