Package Health

plugin/owc-signicat-openid

Healthy and suitable to use, with some maintenance caveats. It has frequent recent releases, an active non-archived repository, and organizational backing, but recent work is concentrated in one contributor and the project lacks a security policy.

Latest v3.2.4PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo bus factorcaution

All three recent commits came from one contributor, leaving a narrow practical maintainer base. Organizational ownership provides some handoff capacity, but no second active contributor is shown.

Repo commit activitycaution

The repository recorded three commits in the last three months, so activity has not stopped. The volume is modest relative to the frequent registry release history.

Repo issue activitycaution

There was one new issue and one new pull request in the last month, but none were closed or merged. This shows some activity, although follow-through is limited in the observed period.

Repo popularitycaution

The repository has zero stars and forks and only three watchers. Popularity is supporting evidence rather than a verdict, but these counts provide little independent evidence of broad community support.

Repo toolingcaution

The project uses Composer build tooling, which supports reproducible package construction. No repository security-scanning tool was detected, leaving a modest transparency gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Yard | Digital Agency

Direct Dependencies

DependencyLast ReleaseScore
odan/session
Version ^6.0
php-di/php-di
Version ^7.0
psr/container
Version ^1.1
guzzlehttp/psr7
Version ^1.9.1 || ^2.5.1
monolog/monolog
Version ^3.0

Weekly Downloads

Info

Last Published
2 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform