Package Health

oas-php/resolver

The package has tests, a README, and organizational ownership. Its pre-1.0 release line has not advanced since December 2022, while recent repository activity is absent, so pinning this version carries maintenance risk.

Latest v0.1.3PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has had no release in roughly three years: its latest release was December 8, 2022, despite four releases overall. This materially raises abandonment and compatibility risk.

Repo commit activitycaution

There were zero commits and zero active maintainers in the three months measured. That is a concrete sign of currently limited maintenance capacity, partially offset by the repository push in February 2025.

Repo toolingcaution

The project uses Composer for builds, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a standalone adoption blocker.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations unclear. The package's tests and organizational backing provide some context, but do not replace a published process.

Version stabilitycaution

The latest version remains below 1.0, so compatibility guarantees are limited. It is not marked as a prerelease, which provides some compensation but does not remove the maturity concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kuba Biernacki

Direct Dependencies

DependencyLast ReleaseScore
nikic/iter
Version ^2.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/simple-cache
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform