Package Health

webignition/php-basil-model-provider

Its small, tested codebase is licensed, but security practices and workflow pinning are limited. The repository remains available rather than archived, which reduces—but does not remove—the maintenance concern.

Latest 0.11PackagistPackagist

35%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no distinct replacement identified. This is a direct warning against adopting the release despite the otherwise usable artifact.

Release historydanger

The package has 12 releases since August 2019, but none in the last 12 months and the latest release was January 17, 2022. That long release gap indicates substantial abandonment risk.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the extended release gap and limited evidence of ongoing maintenance.

Security policycaution

The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is less severe than the abandonment indicators.

Workflow auditcaution

All 10 analyzed GitHub Actions references are unpinned, which weakens build reproducibility and supply-chain hygiene. The audit found no untrusted checkouts, script injection, or high-severity findings, so this remains a caution rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jon Cram

Direct Dependencies

DependencyLast ReleaseScore
webignition/basil-models
Version >=0.60,<1
webignition/php-basil-context-aware-exception
Version >=0.5,<1

Weekly Downloads

Info

Last Published
4 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform