Package Health

playtini/mautic-api-library

The package includes a substantial README, tests, and a clear MIT license. Workflow hygiene is weak, with high-confidence template-injection findings and unpinned container images, while the organization-backed repository remains unarchived.

Latest 3.1.1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

Version 3.1.1 was the only release, published 751 days ago, with no releases in the last 12 months. This is a meaningful maintenance concern despite the repository having been pushed more recently.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the past three months. That indicates currently inactive development and raises abandonment risk, even though the repository is not archived.

Security policycaution

No repository security policy was found. For a maintained library this is a transparency gap, although it is less significant than the release and commit inactivity.

Workflow auditcaution

The single workflow was fully analyzed but has two high-confidence template-injection findings and a high-confidence unpinned-image finding, plus all six action references are unpinned. These are workflow hygiene and supply-chain concerns, though no untrusted checkout or dangerous trigger was reported.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ~1.0 || ~2.0 || ~3.0
—
—
guzzlehttp/psr7
Version ^2.4
—
—
psr/http-client
Version ^1.0
—
—
php-http/discovery
Version ^1.15
—
—
psr/http-client-implementation
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform