Package Health

praveendias1180/a2a-php

It has a clear license, substantial documentation, repository tests, and a security policy. A single publisher and no security-scanning tooling leave less operational depth.

Latest v1.0.0PackagistPackagist

69%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Maintainerscaution

Only one registry account has publishing access, limiting visible publishing redundancy even though the repository itself is active and documented.

Project backingcaution

The repository is owned by an individual rather than an organization, so the single-publisher limitation is not offset by visible organizational backing.

Release historycaution

The package is only 0 days old, with four releases arriving within roughly 1 hour, so it has not demonstrated long-term maintenance yet.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected, leaving a modest repository-hygiene gap.

Workflow auditcaution

All five workflows were analyzed with no detected injection or secret-handling findings, and four use read-only permissions. However, all 36 action references are unpinned and one workflow grants top-level write access, creating a reproducibility and least-privilege caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Praveen Dias

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0 || ^3.0
—
—
psr/clock
Version ^1.0
—
—
google/protobuf
Version ^4.33 || ^5.0
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.1
—
—

Weekly Downloads

Info

Last Published
1 hour ago
Created
18 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform