Package Health

phpolar/mysql-storage

Workflow hygiene is imperfect, with unpinned actions and inherited secrets increasing maintenance risk. The package is otherwise clearly structured, licensed, tested in the repository, and backed by security tooling.

Latest 1.0.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

Six releases were published within the last 12 months, but all occurred between December 1 and December 19, 2025, showing an initially active burst rather than sustained release activity.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, a meaningful maintenance concern for a package intended to be depended on.

Repo issue activitycaution

There are no new or closed issues in the last month and two open pull requests, suggesting limited recent community activity but not clear abandonment by itself.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this modestly reduces maturity evidence but does not determine the verdict.

Workflow auditcaution

All eight workflows were analyzed, but all 17 action references are unpinned, one high-confidence finding uses a floating container image tag, and several workflows inherit secrets. No untrusted checkout or script-injection sink was found, so this is a hygiene and maintenance caution rather than a standalone severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
phpolar/storage
Version ^7.0

Weekly Downloads

Info

Last Published
9 months ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform