Package Health

ublaboo/api-router

The repository remains active, tested, licensed, and backed by an organization, with a release published recently. Its workflows use seven unpinned actions and inherit secrets in one coverage workflow. Use contributte/api-router instead, as listed by the registry.

Latest v7.0.0PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and identifies contributte/api-router as its replacement. This is a severe adoption risk even though the repository remains active.

Repo commit activitycaution

There were no commits and no active maintainers in the three months measured. That suggests limited recent development capacity, despite the recent release and repository push evidence.

Repo toolingcaution

The repository uses Composer and Make, but no security-scanning tools were detected. This is a hygiene gap rather than a standalone dependency risk.

Workflow auditcaution

All four workflows were analyzed with no untrusted checkouts or script injections, but all seven action references are unpinned and one high-confidence medium-severity finding reports inherited secrets in coverage.yml. These are workflow hygiene and exposure concerns, not a standalone reason for a critical score.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pavel Janda

Direct Dependencies

DependencyLast ReleaseScore
nette/di
Version ^3.2.2
—
—
nette/http
Version ^3.3.0
—
—
contributte/utils
Version ^0.6.0 || ^0.7.0
—
—
nette/application
Version ^3.2.5
—
—

Weekly Downloads

Info

Last Published
9 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform