Package Health

web-id/persil

Clear documentation, licensing, repository tests, and a security policy improve day-to-day confidence. Pin 3.0.0 rather than relying on future updates.

Latest 3.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

The package has made four releases since October 2021 but none in the last 12 months; the latest release was in October 2023. This indicates a prolonged maintenance gap, although the release history is established rather than abandoned from the outset.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months. Combined with the old latest release, this raises meaningful abandonment and compatibility risk.

Repo popularitycaution

The repository has only 2 stars, 1 fork, and 1 watcher, so there is little visible community support or independent usage evidence. Low popularity is supporting caution rather than a verdict on its own.

Repo toolingcaution

The project uses Composer and Make, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, partly offset by the repository's security policy and workflow checks.

Workflow auditcaution

All three workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 7 action references are unpinned, leaving a supply-chain hygiene weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leo Tiollier

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^10.28.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform