Package Health

marcosh/lamphpda-validation

Composer tooling and Psalm scanning provide useful build and code-quality support, and the package has a clear license. A single maintainer and small user base leave limited redundancy when maintenance is needed.

Latest 0.1.0PackagistPackagist

54%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

One registry maintainer is consistent with a user-owned project, but it provides little contributor redundancy if the maintainer becomes unavailable.

Release historycaution

This is the only release, published about two years ago, with no releases in the last 12 months. The linked repository is still active rather than archived, but release evidence is thin.

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the last three months. That indicates limited recent maintenance, although it is not proof of abandonment by itself.

Security policycaution

The repository has no published security policy. For a small library this is a transparency gap, even though the absence does not indicate a security defect.

Workflow auditcaution

All 9 analyzed action references are unpinned, reducing build reproducibility and leaving dependency versions exposed to upstream changes. The audit found no untrusted checkouts, script injection, or broad top-level write permissions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marco Perone

Direct Dependencies

DependencyLast ReleaseScore
marcosh/lamphpda
Version ^3.1.1
—
—
giorgiosironi/eris
Version ^1.0.0-rc2
—
—
marcosh/lamphpda-optics
Version ^0.1
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform