Package Health

opportus/sls-client

The documented roadmap still lists core features, validation, tests, and benchmarks as unfinished, and the project has no security policy. The MIT license, README, and repository tests provide useful transparency, but do not offset the maintenance risk.

Latest v1.0.0-alpha.1PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has had only one release, first published about 6 years and 9 months ago, with no releases in the last 12 months. This is strong evidence of abandonment risk.

Repo commit activitydanger

There were no commits and no active maintainers in the last 3 months, consistent with the repository's last push being about 6 years and 9 months ago. This materially increases abandonment risk.

Package scaffoldingcaution

The package includes a README and the repository has tests, but the README explicitly lists cache support, unit and functional tests, benchmarks, all SLS methods, and request validation as unfinished. The GitHub release confirms release transparency for this version, but not implementation completeness.

Repo toolingcaution

The repository uses Composer, which supports reproducible project builds, but it has no security scanning tools. That is a maintenance and transparency gap for a package handling service requests.

Security policycaution

No security policy was found in the linked repository. This weakens the project's disclosure and response process, although it is not by itself evidence of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Clément Cazaud

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform