Package Health

shyim/mjml-php

This is a promising but still young package with strong basic transparency and packaging: it has an MIT license, README, changelog, tests in both the artifact and repository, a coherent 247-file source tree, no install-time lifecycle scripts, a matching repository, and recent release and commit activity. The main concerns are that version 0.2.1 is not a stable major release, the project is only 111 days old, all four commits in the last three months came from one contributor, and the repository lacks a security policy and explicit top-level GitHub Actions permissions. It appears reasonable to evaluate for use, but its maturity and bus-factor risks warrant monitoring and a fallback plan for important production dependencies.

Latest 0.2.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Project backingcaution

The repository owner is an individual user rather than an organization, so the single-maintainer concentration is not visibly offset by organizational backing.

Release historycaution

Five releases over 111 days, with a median interval of about 20 days and a release as recent as the collection date, show active early-stage development; the short history still limits evidence of long-term stability.

Repo bus factorcaution

One contributor made 100% of the four recent commits, creating a genuine single-maintainer continuity risk; the repository is user-owned rather than organization-owned, so there is no shown organizational compensation.

Repo commit activitycaution

There were four commits in the last three months and one active maintainer, indicating current activity but a relatively modest maintenance pace for assessing longer-term resilience.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap that is relevant to a dependency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tijsverkoyen/css-to-inline-styles
Version ^2.2

Weekly Downloads

Info

Last Published
12 days ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform