Package Health

psx/api-bundle

Usable with caveats: the package is licensed, documented, tested, and backed by an active repository with sensible tooling. However, it has had no release or commit activity for about one year, and the repository lacks a security policy and explicit workflow token permissions.

Latest v0.1.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers over the last three months, consistent with the roughly one-year release gap and raising maintenance risk.

Dependency profilecaution

Six runtime dependencies are declared, including related PSX components and Symfony, which is a meaningful dependency surface but is coherent with the bundle's stated API-building role.

Release historycaution

Only three releases exist and there have been no releases in the last 12 months, indicating a slow or stalled release cadence for a relatively young package.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations unclear for a package intended to handle web APIs.

Token permissionscaution

The CI workflow does not declare top-level token permissions, reducing transparency about least-privilege settings even though no write permissions were observed.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christoph Kappestein

Direct Dependencies

DependencyLast ReleaseScore
psx/api
Version ^7.2
—
—
psx/sql
Version ^4.1
—
—
psx/data
Version ^7.0
—
—
psx/schema
Version ^7.2
—
—
symfony/framework-bundle
Version ^6.4|^7.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform