Package Health

theodo-group/llphant

LLPhant 1.0.2 appears to be a healthy, actively maintained dependency: it has a mature release history with 137 releases and 20 releases in the last 12 months, the current stable release is not deprecated, and the linked organization-owned repository is active, substantial, and clearly matches the package. Repository tests, CI tooling, Dependabot, TruffleHog, and a clean workflow risk profile provide useful transparency and engineering safeguards. The main concerns are that recent commit activity is modest and concentrated in one contributor, there is no security policy, and workflows do not declare top-level permissions; these are meaningful hygiene gaps but are partly offset by three active contributors, organizational backing, ongoing releases, and security scanning.

Latest 1.0.2PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitycaution

There were 10 commits by three active maintainers in the last three months, showing continued work, but the pace is modest for a fast-moving integration library.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting expectations and response procedures undocumented.

Token permissionscaution

All three workflows lack top-level token permissions declarations. Although none declares top-level write access, explicitly restricting permissions would provide stronger CI hardening.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Maxime Thoonsen

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
guzzlehttp/psr7
Version ^2.7
—
—
psr/http-client
Version ^1.0.3
—
—
yethee/tiktoken
Version ^0.10.0
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform