Package Health

phpsagas/orchestrator

The package has a clear README, matching repository, source tests, and an MIT license. Its repository has not been pushed since June 2021, and there has been no recent issue or pull-request work, leaving maintenance risk high.

Latest 0.0.0PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has only one release, published about five years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a library dependency.

Project backingcaution

The repository owner matches the registry namespace, and the owner is an individual account rather than an organization. This supports package identity but offers limited evidence of broader maintenance capacity.

Repo issue activitycaution

There is one open issue but no new or closed issues and no pull-request activity in the last month. Combined with the old repository push, this suggests maintenance has stopped.

Repo toolingcaution

The repository uses Make and Composer build tooling, which supports reproducible project tasks. No security scanning tools were detected, a minor transparency and hygiene gap for a maintained dependency.

Repository archivedcaution

The linked repository is not archived, which is a positive maintenance signal. However, its last push was about five years ago, so this does not offset the broader inactivity evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Oleg Filatov

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1
phpsagas/contracts
Version ^0.0

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform