Package Health

rumenx/php-sitemap

This is a healthy, well-documented and actively maintained release with a stable major version, a matching source repository, tests, changelog, license, security policy, CI, and security scanning. Recent repository activity and two merged pull requests indicate ongoing maintenance, while the main concern is concentration of recent commits in one contributor and a relatively modest release cadence of five releases over 401 days. The available evidence supports depending on it, with normal single-maintainer continuity risk rather than a significant abandonment or transparency concern.

Latest v1.0.4PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access. This is a modest publishing continuity concern, though the linked repository identifies the same individual as its owner and active contributor, so it does not indicate an ownership mismatch.

Project backingcaution

The repository is owned by a user rather than an organization, so there is no organizational handoff capacity to offset the concentrated maintainer base.

Repo bus factorcaution

All four commits in the last three months came from one contributor, giving a 100% top-contributor share and creating a genuine single-person continuity risk.

Repo commit activitycaution

Four commits were made in the last three months by one active maintainer, demonstrating recent work but also showing limited maintenance breadth.

Token permissionscaution

Two workflows declare read-only permissions and none declare top-level write access; one style workflow lacks top-level permissions, which is a minor hardening gap but not evidence of excessive privilege.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rumen Damyanov

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
20 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform