Simple graphql server
68%
Total Score
50
50
94
90
Seven runtime dependencies, including the GraphQL framework, container, cache, upload, and PSR-7 components, create meaningful update and compatibility surface for a small library, though the dependencies are clearly documented in the README.
The registry namespace and repository owner match, but both are tied to an individual user rather than an organization, leaving a relatively narrow visible ownership base.
There were zero commits and zero active maintainers in the last three months. The recent release and prior release cadence provide some compensation, but this is still a concrete maintenance risk for a library dependency.
The repository has zero stars and forks and only one watcher, indicating little public validation or contributor reach. Popularity is supporting evidence rather than a decisive health measure, so this lowers confidence more than it determines the verdict.
The repository has no security policy. That is a transparency gap for a server library, although the absence of reported dangerous workflows and the presence of GitGuardian scanning provide limited compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^7.4 | — | — |
league/container Version ^5.2 | — | — |
ecodev/graphql-upload Version ^8.0 | — | — |
laminas/laminas-diactoros Version ^3.5 | — | — |
thecodingmachine/graphqlite Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.