Package Health

webproject-xyz/docker-api-client

This release appears healthy and reasonably safe to depend on: it has a stable non-prerelease version, frequent recent releases, an active non-archived repository, tests and changelog coverage, explicit MIT licensing, and recent activity from two contributors. The main reservations are modest repository popularity, absent security scanning and security policy, and GitHub Actions permission and untrusted-checkout concerns in the release workflow; these warrant review but do not outweigh the strong maintenance and project-structure evidence.

Latest 1.5.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

Both workflows were analyzed with no script injection or pull_request_target findings, but the release workflow contains an untrusted checkout in a workflow_run context, creating a meaningful workflow-hardening concern.

Repo popularitycaution

Two stars, zero forks, and one watcher indicate very limited external adoption and independent review. Popularity is supporting evidence rather than a verdict, so this is a caution rather than a severe health failure.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning lowers supply-chain transparency somewhat, though it is not by itself evidence of an unhealthy package.

Security policycaution

The repository has no SECURITY.md or equivalent security policy, leaving vulnerability-reporting and response expectations unclear.

Token permissionscaution

The release workflow lacks top-level token permissions, and the CI workflow declares top-level write permissions; these defaults are broader or less explicit than ideal and warrant workflow review.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Benjamin Fahl

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^7.4.15 || ^8.0
—
—
symfony/runtime
Version ^7.4.14 || ^8.0
—
—
symfony/serializer
Version ^7.4.15 || ^8.0
—
—
symfony/http-client
Version ^7.4.15 || ^8.0
—
—
phpstan/phpdoc-parser
Version ^2.3.3
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform