Package Health

waynestate/waynestate-api

This is a small, long-lived MIT-licensed PHP API wrapper with a clear README, a compact and coherent package tree, no install-time lifecycle scripts, stable versioning, and no registry deprecation. The linked organization-owned repository is not archived and shows recent release and commit activity, but maintenance capacity is thin: only one release occurred in the last 12 months, there is one active contributor with all recent commits, and the package and repository contain no tests or changelog. The absence of a security policy and security scanning further reduces transparency, although the package's minimal scope and organization backing partially mitigate the single-maintainer risk. It is usable with caution rather than an obviously unsafe dependency.

Latest 1.2.5PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access, which is a concentration risk; however, the repository is organization-owned, making a short registry maintainer list less concerning than it would be for an individual-owned project.

Package scaffoldingcaution

A substantive README documents installation, usage, and contribution steps, but neither the artifact nor repository contains tests or a changelog. For a small API wrapper this is a real maintenance and verification gap.

Release historycaution

The package has existed for roughly 11.6 years with nine releases, but only one release occurred in the last 12 months and the median release interval is about 319 days. This indicates continuity but slow maintenance cadence.

Repo bus factorcaution

All recent commits came from one contributor, creating a high individual concentration risk. Organization ownership provides some potential handoff capacity, but no second active contributor is evidenced.

Repo commit activitycaution

There was one commit from one active maintainer in the last three months, showing current activity but very limited maintenance throughput.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nick DeNardis

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
26 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform