Package Health

reddingwebdev/abuseipdb

Documentation, tests, and release notes make the package easy to evaluate. Its very short history and unpinned CI actions leave limited evidence of long-term maintenance and build reproducibility; pin this version only if that trade-off is acceptable.

Latest 0.1.1PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package is less than one day old with only two releases, so there is too little history to establish sustained maintenance. The rapid second release is a small positive but does not offset the limited track record.

Repo commit activitycaution

There were no commits or active maintainers in the measured three-month window. Because the repository was created very recently, this is partly explained by its age, but it still provides no evidence of sustained maintenance yet.

Security policycaution

The repository has no security policy. For a client handling API credentials and external HTTP calls, this is a transparency gap, although it is not evidence that the package is unsafe by itself.

Version stabilitycaution

Version 0.1.1 is not a prerelease, but it is still below a stable major version and the package has no established release history. This indicates a potentially changing API rather than an immediate abandonment risk.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, but all 11 action references are unpinned. Missing top-level permissions is acceptable here, while unpinned actions reduce build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jason J. Olson

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1 || ^2.0 || ^3.0
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/http-message
Version ^1.1 || ^2.0
—
—
php-http/discovery
Version ^1.19
—
—

Weekly Downloads

Info

Last Published
6 days ago
Created
7 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform