Package Health

retailcrm/mg-bot-api-client-php

The package includes tests, a clear README, an MIT license, and a release for this version. The main concern is no repository commit activity in the last three months, alongside no security scanning and unpinned workflow actions.

Latest v1.4.22PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Dependency profilecaution

Nine runtime dependencies, including Guzzle, Symfony components, and JMS Serializer, create a meaningful dependency surface for a client library but remain consistent with its functionality.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign of currently limited maintenance capacity despite the recent release.

Repo popularitycaution

The repository has only 3 stars and 16 forks, so independent adoption evidence is limited; popularity is supporting evidence and does not outweigh the project’s other signals.

Repo toolingcaution

Composer and Make are used for builds, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no published security policy, making vulnerability reporting and response expectations less clear for consumers.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

RetailCRM

Direct Dependencies

DependencyLast ReleaseScore
symfony/intl
Version 5.4.*|^6
—
—
symfony/cache
Version 5.4.*|^6
—
—
jms/serializer
Version 3.*
—
—
guzzlehttp/guzzle
Version 7.*
—
—
symfony/validator
Version 5.4.*|^6
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform