Package Health

soyhuce/phpinsights-formatter

Usable with caveats: the package is licensed, correctly backed by its repository, and has release documentation and security tooling. However, it has had no registry release in nearly three years and no commits or active maintainers in the last three months, so ongoing maintenance is uncertain.

Latest 2.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months, a concrete sign that maintenance may have stalled despite the repository not being archived.

Dangerous workflowscaution

One workflow uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger can run with elevated repository context; no untrusted checkout or script-injection findings were detected.

Release historycaution

Although the package released regularly at first, its latest registry release was nearly three years ago and it has had no releases in the last 12 months, which raises maintenance and compatibility concerns.

Repo issue activitycaution

There are no open issues and four open pull requests, but none were merged or newly created in the last month, suggesting limited recent project activity.

Token permissionscaution

Four of five workflows omit top-level permissions and the Dependabot auto-merge workflow grants write access, leaving workflow token scope less explicit than ideal.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Bastien Philippe

Direct Dependencies

DependencyLast ReleaseScore
nunomaduro/phpinsights
Version ^2.3

Weekly Downloads

Info

Last Published
2 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform