Package Health

socialdept/atp-testnet

This release appears healthy and reasonably safe to depend on: it is actively released, not deprecated, backed by a non-archived organization-owned repository, and has matching source, documentation, tests, CI workflows, and a clear MIT license. The main reservations are that the project is young and still on the 0.x line, recent activity is concentrated in one of two contributors, and the repository lacks a security policy, dedicated security scanning, and explicit top-level workflow token permissions. These are meaningful hygiene and continuity concerns, but they do not outweigh the strong evidence of current maintenance and coherent package provenance.

Latest v0.2.3PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

Two contributors remain active, but the leading contributor made 5 of 6 recent commits, creating some continuity risk; organization backing provides partial mitigation.

Repo popularitycaution

The repository has only 6 stars and no forks or watchers, indicating limited adoption evidence; popularity is supporting evidence, so this is a caution rather than a health verdict.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured, leaving a repository security-hygiene gap.

Security policycaution

The repository has no security policy, which weakens vulnerability-reporting transparency and response expectations.

Token permissionscaution

Neither workflow declares top-level token permissions. Although no workflow requests top-level write access, explicit least-privilege permissions would provide stronger CI hardening.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/process
Version ^7.0|^8.0
guzzlehttp/guzzle
Version ^7.0
textalk/websocket
Version ^1.5
socialdept/atp-cbor
Version ^0.2

Weekly Downloads

Info

Last Published
15 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform