Package Health

patrickriemer/oci-adapter

The package has a clear README, matching repository, and MIT license. Its small dependency surface and lack of install scripts limit operational exposure, but maintenance confidence remains weak.

Latest v1.0.0PackagistPackagist

44%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has made only three releases, all within a short period ending in November 2024, and none in the last 12 months. This strongly suggests abandonment risk for a storage integration.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with a project that has not been maintained since November 2024. This is a substantial abandonment concern.

Maintainerscaution

One registry maintainer is consistent with the user-owned repository, but it creates a thin bus factor with no observed activity to show continuing support.

Package scaffoldingcaution

A 1,506-character README documents installation, configuration, and OCI-specific behavior, which supports consumers. The absence of tests and a changelog is not a packaging defect for this artifact, but it leaves less evidence of compatibility and change tracking.

Project backingcaution

The package and repository are owned by the same individual account, with no organization backing shown. That makes the single-maintainer activity gap more consequential.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Patrick Riemer

Direct Dependencies

DependencyLast ReleaseScore
league/flysystem
Version ^3.12
illuminate/support
Version ^v11.9.2
hitrov/oci-api-php-request-sign
Version dev-main

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform