Package Health

php-ship/ship

Usable with caveats: this is a well-documented, licensed package with matching organization-backed source and repository tests, but it is only one day old with four rapid releases and no established commit history. Its single workflow lacks explicit token permissions and the repository has no security policy.

Latest v0.2.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package is only 1 day old and has four releases, with a median interval of about 10 hours. This shows active initial iteration but provides almost no long-term maintenance evidence.

Repo commit activitycaution

There were no commits or active maintainers recorded in the last 3 months, so there is no established maintenance track record; the package's one-day age limits how strongly this should be interpreted.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher. This provides little external validation, though low popularity alone is not evidence that a small new package is unsafe to adopt.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tooling is detected. The missing scanning layer is a modest transparency and maintenance concern.

Security policycaution

No repository security policy is present, leaving vulnerability-reporting expectations unclear for a package that runs development environment commands.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

php-ship

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^7.0 || ^8.0
symfony/console
Version ^7.4 || ^8.0
symfony/process
Version ^7.0 || ^8.0
symfony/filesystem
Version ^7.0 || ^8.0

Weekly Downloads

Info

Last Published
4 days ago
Created
5 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform