Package Health

simpod/clickhouse-client

The repository is actively maintained, has tests, clear documentation, and published release notes. A concentrated maintainer base, missing security policy, and unpinned workflow actions add avoidable maintenance and build-integrity concerns.

Latest 0.8.3PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has 38 releases over about six years, but none in the last 12 months; the latest registry release was published over a year ago. Active repository commits partly offset the pause, but release availability remains a concern.

Repo bus factorcaution

One contributor made 37 of 38 recent commits, leaving maintenance highly concentrated. The second contributor provides some coverage, but not enough to remove the continuity concern.

Security policycaution

The repository has no security policy. This does not show a security defect, but it leaves vulnerability reporting and response expectations less transparent.

Version stabilitycaution

Version 0.8.3 is not a prerelease, but the package remains below 1.0, so compatibility expectations are somewhat less stable than for a mature major release.

Workflow auditcaution

All four workflows were analyzed without high-confidence findings or unsafe triggers, but all 18 action references are unpinned. The workflows also lack top-level permissions blocks, which is acceptable here, while unpinned actions weaken reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Simon Podlipsky

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3
—
—
guzzlehttp/psr7
Version ^2.6
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/http-message
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform