Package Health

sandermuller/json

Documentation, licensing, and repository activity are solid, with release notes for this version and two active contributors. Install-time scripts and a concentrated maintainer base add practical review points for a young project.

Latest v0.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These add supply-chain and reproducibility review points even though no other provided signal shows malicious behavior.

Maintainerscaution

The registry has one publishing maintainer. The linked repository is user-owned rather than organization-owned, so there is limited visible publishing redundancy, though repository activity shows another contributor.

Project backingcaution

The package and repository are consistently owned by the same individual, and the repository is user-owned. This supports identity consistency but provides less organizational maintenance backing.

Release historycaution

The package is only 60 days old and has two releases, both published within roughly 5 hours, so there is limited evidence of sustained release maintenance.

Repo bus factorcaution

Two contributors were active, but the top contributor made about 65% of recent commits. That is a modest concentration risk for a user-owned project, not a severe single-maintainer failure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sander Muller

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 months ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform