Package Health

ngyuki/phpower

The MIT license, matching repository, README, and repository test suite provide useful transparency. Unpinned CI references and no security policy limit maintenance hygiene, while the package’s small scope and no install scripts reduce adoption risk.

Latest v0.0.3PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has only three releases and none in the last 12 months; its latest release was in March 2022, indicating prolonged release inactivity.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment concerns.

Security policycaution

The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.

Workflow auditcaution

All 7 analyzed action references are unpinned, which weakens build reproducibility. The reported cache-poisoning findings are low-confidence hygiene warnings, not severe risks on their own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Toshiyuki Goto

Direct Dependencies

DependencyLast ReleaseScore
phpunit/phpunit
Version ^9.5
symfony/var-dumper
Version ^5.3.7|^6.0
microsoft/tolerant-php-parser
Version ^0.1

Weekly Downloads

Info

Last Published
4 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform