Package Health

ringcentral/glip-botman

It has a clear MIT license, tests, a substantial README, organization ownership, and no install-time scripts. The package offers little evidence of ongoing maintenance, so future PHP or dependency compatibility may require taking on ownership.

Latest 2.0.0PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has had only two releases, both in October 2017, with no releases in the last 12 months. This strongly limits evidence that the published dependency is maintained for current consumers.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, despite its last push being in June 2021. That indicates a substantial maintenance gap for a package consumers may still need to update.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, while two issues and two pull requests remain open. This is consistent with low project activity, though the open items alone do not establish abandonment.

Repo toolingcaution

The repository uses Composer and Make, which supports repeatable project operations, but it reports no security scanning tools. That leaves less automated evidence of security maintenance.

Security policycaution

The linked repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, although it is a secondary concern compared with the package's long release and commit gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

RingCentral, Inc.
Anil Kumar

Direct Dependencies

DependencyLast ReleaseScore
mpociot/botman
Version ^1.5
—
—
guzzlehttp/psr7
Version ^1.4.2
—
—
vlucas/phpdotenv
Version ^2.2
—
—
guzzlehttp/guzzle
Version ^6.2.3
—
—
symfony/event-dispatcher
Version ^2.7|^3.3.2
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform