Package Health

simsoft/validator

This release appears generally safe to depend on from a maintenance and transparency perspective: it has a multi-year release history, five releases in the last 12 months, a stable non-prerelease version, an active non-archived repository, documented licensing, repository tests, documentation, a changelog, and no install-time lifecycle scripts. The main concerns are limited recent activity—one commit from one contributor in the last three months—and minimal repository adoption, which increase bus-factor and continuity risk. The workflow lacks explicit top-level token permissions and the repository has no detected security-scanning tool, but its analyzed workflow shows no dangerous checkout, injection, or elevated-write patterns.

Latest 4.0.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which creates publishing continuity risk; however, this is administrative access information and does not outweigh the repository's observed activity.

Project backingcaution

The repository is owned by a personal GitHub user rather than an organization, so there is no demonstrated organizational maintenance handoff capacity to offset the concentrated contributor base.

Repo bus factorcaution

All recent commits came from one contributor, producing a complete short-term concentration of commit activity; the user-owned repository provides no organizational backing to compensate for this concentration.

Repo commit activitycaution

Only one commit was recorded in the last three months from one active maintainer, showing limited recent development activity and raising maintenance-continuity concerns despite the recent release history.

Repo popularitycaution

The repository has zero stars and forks and only two watchers, so there is little external adoption evidence; this is supporting caution rather than a standalone health verdict.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

V. Zang, Loo

Direct Dependencies

DependencyLast ReleaseScore
symfony/validator
Version ^8.1
symfony/translation-contracts
Version ^3.5

Weekly Downloads

Info

Last Published
15 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform