Package Health

stolt/llms-txt-php

This release appears healthy and suitable to depend on: it is actively released, stable, non-deprecated, licensed, backed by a matching repository, and supported by recent commit activity, tests, changelog, and GitHub releases. The main reservations are that recent commits are highly concentrated in one of two contributors, the repository has no security policy or configured security-scanning tool, and its workflows do not declare top-level token permissions. These are meaningful hygiene and continuity concerns, but they do not outweigh the package's active maintenance and otherwise coherent publication structure.

Latest v4.3.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access. Because the repository is user-owned rather than organization-owned, this is a modest publishing continuity concern, though active repository work provides some compensation.

Project backingcaution

The source repository is owned by the user account raphaelstolt rather than an organization, so there is no organizational maintenance-backup evidence. Active commits and releases partially compensate for that limitation.

Repo bus factorcaution

One contributor made 25 of 26 commits, or about 96%, in the last three months. A second contributor remains active, but the extreme concentration creates a genuine continuity risk for this user-owned project.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool is configured. The missing security automation is a hygiene gap, not evidence of abandonment or maliciousness.

Security policycaution

The repository has no security policy. This reduces vulnerability-reporting transparency, but it is a moderate hygiene gap rather than a standalone dependency-blocking risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Raphael Stolt

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
15 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform