Package Health

statsig/statsigsdk

Documentation, tests, release notes, and an ISC license are present, with no install-time scripts. The organization-backed repository has security scanning, but all five workflow actions are unpinned and the repository does not identify this package.

Latest 3.7.2PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. That is a meaningful maintenance concern, even though the registry shows recent releases.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, while 2 pull requests remain open. Together with zero recent commits, this suggests limited current project activity.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention this package. That leaves some uncertainty about package-to-source ownership, despite the organization-backed repository.

Security policycaution

The repository has no security policy. This weakens vulnerability-reporting transparency, although the separate repository tooling signal shows Aikido security scanning.

Workflow auditcaution

All 5 analyzed action references are unpinned, so workflow dependencies can change without a reviewed version update. The audit found no untrusted checkouts, script injection, excessive top-level write permissions, or other reported findings.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2024-10210 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
statsig/statsigsdk is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor in versions 3.2.0 - 3.3.0.
3.2.0 - 3.3.0
Medium

Package versions

Maintainers

Statsig

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.0
—
—
ua-parser/uap-php
Version 3.9.*
—
—
statsig/ip3country
Version ^0.1.0
—
—

Weekly Downloads

Info

Last Published
10 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform