Package Health

phpolar/sqlite-storage

The repository includes tests, a changelog, a security policy, and automated security scanning. Workflow controls need tightening because all 17 action references are unpinned and several workflows inherit secrets.

Latest 1.1.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo commit activitydanger

There were zero commits and zero active maintainers during the last three months. For a package released less than a year ago, this is a meaningful sign that maintenance may have stopped.

Release historycaution

The package is about 293 days old with six releases, all within the last 12 months and concentrated in an initial burst. This shows publishing activity but not sustained maintenance, especially alongside the lack of recent commits.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no external adoption signal to offset the maintenance concerns.

Workflow auditcaution

The audit analyzed all eight workflows with no failed files or untrusted-checkout findings, but all 17 action references are unpinned and high-confidence secrets-inherit findings appear across several reusable workflows. These are meaningful supply-chain hygiene weaknesses, though not severe on their own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
phpolar/storage
Version ^7.0

Weekly Downloads

Info

Last Published
9 months ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform