Package Health

php-soap/engine-integration-tests

The package is clearly documented, licensed, and has a recent stable release with published notes. Repository activity was absent in the last three months, while its only workflow uses unpinned actions and has no security policy.

Latest 1.12.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dependency profilecaution

The package has seven runtime dependencies, including PHPUnit and SOAP-related libraries. That is a meaningful dependency surface for an integration-test package, but it is coherent with the package's stated purpose.

Repo commit activitycaution

No commits and no active maintainers were recorded in the last three months. This is a maintenance warning, although the package also had a recent release during that period.

Security policycaution

The repository has no security policy. That is a transparency and maintenance gap, though the package is a test component rather than a production service.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but both action references are unpinned and the workflow has no top-level permissions block. These are modest reproducibility and least-privilege gaps, not severe risks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Toon Verwerft

Direct Dependencies

DependencyLast ReleaseScore
veewee/xml
Version ^4.8
—
—
php-soap/xml
Version ^1.9
—
—
php-soap/engine
Version ^2.16
—
—
php-vcr/php-vcr
Version ^1.6.0
—
—
phpunit/phpunit
Version ~12.3
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform