Package Health

pheature/mezzio-toggle

Tests, release notes, and a clear BSD-3-Clause license improve maintainability and transparency. Dependabot and Psalm provide useful safeguards, but all workflow actions are unpinned and no security policy is published.

Latest 0.7.1PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has had no release in over three years, despite a roughly monthly median interval across its eight releases. This strongly raises abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating inactive maintenance.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting expectations unclear. Dependabot and Psalm provide some compensating security hygiene.

Version stabilitycaution

Version 0.7.1 is not a prerelease, but the 0.x major version signals that compatibility may still change before 1.0. This is a secondary concern beside the maintenance inactivity.

Workflow auditcaution

All 13 analyzed action references are unpinned, weakening build reproducibility and update control. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-severity findings.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

kpicaza
pcs289
xserrat

Direct Dependencies

DependencyLast ReleaseScore
mezzio/mezzio
Version ^3.3
—
—
mezzio/mezzio-helpers
Version ^5.4
—
—
pheature/toggle-model
Version ^0.7
—
—
laminas/laminas-diactoros
Version ^2.6
—
—
pheature/toggle-crud-psr11-factories
Version ^0.7
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform