Package Health

segrax/open-policy-agent

The package includes tests, a substantial README, and release notes for this version. MIT licensing, no install scripts, and a non-archived repository improve transparency, but the lack of security scanning leaves some hygiene gaps.

Latest 0.5.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has 7 releases since December 2019, but none in the last 12 months; its latest release was about 2 years and 6 months ago. This indicates materially slowed maintenance.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since the latest release and increasing abandonment risk.

Repo toolingcaution

The repository uses Make and Composer, but no security scanning tools were detected. The missing scanning is a maintenance and hygiene gap, though it is not evidence of unsafe code by itself.

Security policycaution

No security policy was found in the repository, leaving vulnerability reporting and response expectations undocumented.

Version stabilitycaution

Version 0.5.0 is a stable release rather than a prerelease, but the project remains below major version 1, so compatibility maturity is somewhat limited.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Robert Crossfield

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0|^2.0|^3.0
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/http-message
Version ^1.0 | ^2.0
—
—
splitbrain/php-archive
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform