Package Health

ruudk/graphql-client-code-generator

Usable with caveats: it has frequent releases, a matching public repository, tests, release notes, and clear licensing. The main concerns are its young 0.x status, only two commits from one contributor in the last three months, and an install-time script without a repository security policy or explicit workflow permissions.

Latest 0.5.3PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

A post-install-cmd script runs during installation, increasing installation complexity and the trust placed in package behavior. No provided signal shows that this script is harmless or necessary, so it is a supply-chain hygiene concern.

Project backingcaution

The registry namespace and repository are owned by the same individual, confirming direct ownership rather than a namespace mismatch. Because the owner type is User, this does not provide the continuity of an organization-backed project.

Repo bus factorcaution

All two recent commits came from a single contributor, giving the project a concentrated maintenance base. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset this risk.

Repo commit activitycaution

The repository recorded only two commits in the last three months from one active maintainer. Recent releases show the project is not abandoned, but the low recent activity indicates limited ongoing maintenance capacity.

Repo issue activitycaution

There are no open issues and one open pull request, but there were no new or closed issues or merged pull requests in the last month. This is limited evidence of current community activity, though the recent release provides some compensating maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
sebastian/diff
Version ^9.0
—
—
symfony/finder
Version ^8.0
—
—
symfony/string
Version ^8.0
—
—
phpstan/phpstan
Version ^2.2.1
—
—
symfony/console
Version ^8.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform