Package Health

owenvoke/brightid

A clear README, MIT licensing, repository tests, and no install scripts improve transparency and reduce installation surprises. Unpinned workflow actions and no security policy add smaller maintenance concerns.

Latest v1.0.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has only one release, published about four years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, although the repository remains available.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last three months, following a last push in September 2022. That sustained inactivity materially raises the chance that issues and compatibility problems will go unaddressed.

Repo popularitycaution

The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these very low adoption signals provide little indication of an active user or contributor community.

Security policycaution

The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency and maintenance gap, but not severe on its own.

Workflow auditcaution

Both workflows were analyzed without detected audit findings or untrusted checkouts, and neither grants top-level write access. However, all seven action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
php-http/httplug
Version ^2.2
psr/http-message
Version ^1.0
php-http/discovery
Version ^1.14
php-http/client-common
Version ^2.4
psr/http-client-implementation
Version ^1.0

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform