Package Health

php-etl/json-flow

The package includes tests, a README, an MIT license, and a matching organization-backed repository. Its workflow references are unpinned, and the pre-1.0 version leaves less stability assurance.

Latest v0.3.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The latest registry release was nearly three years ago, with no releases in the last 12 months. This materially increases abandonment and freshness concerns despite the package not being deprecated.

Repo commit activitycaution

There were no commits and no active maintainers in the three months measured. The repository's March 2026 push partly offsets this, but the recent activity window still indicates limited maintenance momentum.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap rather than evidence of a security incident.

Version stabilitycaution

This is a pre-1.0 release, so compatibility guarantees are weaker than for a stable-major package. It is not marked as a prerelease, which provides some compensation.

Workflow auditcaution

The sole analyzed workflow completed fully with no untrusted checkouts, script injection, or audit findings. However, all three action references are unpinned, leaving avoidable update and supply-chain hygiene risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Grégory Planchat

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
php-etl/bucket
Version *
php-etl/bucket-contracts
Version 0.3.*
php-etl/pipeline-contracts
Version 0.5.*

Weekly Downloads

Info

Last Published
2 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform