Package Health

socialdept/atp-client

This release appears generally suitable to depend on: it is actively published, has a matching source repository, tests, a changelog, substantial documentation, a license file, and no deprecation or archive indicators. The main concerns are that the project is still on version 0.x, all 13 recent commits came from one contributor, repository popularity is minimal, and the repository lacks an explicit security policy and top-level workflow permissions; these warrant review and monitoring but do not outweigh the strong maintenance and packaging evidence.

Latest v0.3.4PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

One contributor made all 13 commits in the last three months, creating a significant continuity and abandonment risk. Organization ownership provides some potential handoff capacity, but no second active contributor is shown.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 0 watchers. Popularity is supporting evidence rather than a verdict, but these low counters provide little external validation.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are detected. The build setup is appropriate, while the absent scanning coverage is a transparency and assurance gap.

Security policycaution

The repository has no SECURITY.md or other detected security policy, leaving vulnerability reporting and response expectations undocumented.

Token permissionscaution

Neither workflow declares top-level token permissions. No write permissions are explicitly requested, but the absence of least-privilege declarations is a CI hardening gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

SocialDept

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^11.0|^12.0|^13.0
firebase/php-jwt
Version ^7.0
guzzlehttp/guzzle
Version ^7.0
illuminate/support
Version ^11.0|^12.0|^13.0
phpseclib/phpseclib
Version ^3.0

Weekly Downloads

Info

Last Published
13 days ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform