Package Health

shivammathur/spc

The package is clearly documented, licensed, and provides release notes for this version. Its small workflow is fully audited, but the published release is old enough that pinning it requires extra maintenance caution.

Latest 0.0.5PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historycaution

The latest registry release was about four years ago, with no releases in the last 12 months. The linked repository was pushed more recently, but the registry artifact itself is stale.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. Although the repository was pushed in 2025, the lack of recent activity weakens confidence in ongoing maintenance.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tool was detected. This is a modest repository-hygiene gap rather than evidence that the release is unsafe.

Version stabilitycaution

Version 0.0.5 is not a stable major release, but it is not marked as a prerelease and recent releases have not been prerelease versions.

Workflow auditcaution

The single workflow was analyzed successfully with no detected injection, untrusted-checkout, or other audit findings. Its one action is unpinned, which leaves a small reproducibility and supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Shivam Mathur

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform