Package Health

novastar/auth-api

The package includes tests, a usable README, and an MIT license declaration. Its 11 runtime dependencies include PHPUnit, while one registry maintainer leaves limited visible maintenance capacity.

Latest 1.0.2PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historydanger

The package has only three releases, with the latest on January 11, 2019 and no releases in the last 12 months. This long release gap is strong evidence of abandonment risk.

Dependency profilecaution

The package declares 11 runtime dependencies, including PHPUnit, creating a relatively broad and unusual production dependency surface for an SDK and increasing maintenance burden.

Maintainerscaution

Only one account has registry publish access. This is a thin publishing base and leaves little visible redundancy if that maintainer stops maintaining the package.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the single-maintainer signal is not compensated by visible organizational backing.

Repo issue activitycaution

There are no open issues or pull requests and no recent activity. The clean tracker is not evidence of active maintenance and is consistent with the long inactivity period.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

liuzq

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version 1.32.0
—
—
pimple/pimple
Version ^3.0
—
—
doctrine/cache
Version ~1.6.0
—
—
guzzlehttp/psr7
Version 1.4.2
—
—
monolog/monolog
Version 1.23.0
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform