Package Health

ondrej-vrto/php-linechart

The repository includes tests, release notes, dependency scanning, and a clear MIT license. The long gap since the last registry release and workflow hygiene issues make ongoing maintenance less certain.

Latest 1.1.1PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The latest release was over two years ago, with no releases in the past 12 months. This is a meaningful maintenance concern, although the repository was pushed recently and had three merged pull requests in the last month.

Repo commit activitycaution

There were no commits and no active maintainers in the past three months, which weakens evidence of ongoing development. Recent repository pushes and merged pull requests provide some compensating activity but do not restore a regular release cadence.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations undocumented. Dependabot is enabled, which provides some compensating security practice.

Workflow auditcaution

All 9 analyzed action references are unpinned, and a high-confidence bot-conditions finding reports that actor checks may be spoofable; one workflow also grants top-level write permissions. The pull_request_target workflow has no untrusted checkout or script-injection finding, so this is workflow hygiene risk rather than a severe release risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ondrej Vrťo

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^4.7
spatie/color
Version ^1.5
illuminate/collections
Version ^9.0|^10.0|^11.0

Weekly Downloads

Info

Last Published
2 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform