Package Health

wingify/wingify-fme-php-sdk

This release appears suitable for dependency use, with a clear Apache-2.0 license, substantial documentation, tests, changelog, a matching organization-owned repository, recent publication activity, and no deprecation or archive status. The main concerns are that the package is only 103 days old, repository commit activity is modest and concentrated in one contributor, and the repository lacks a security policy and explicit GitHub Actions token permissions; organization backing and active recent releases partly mitigate the contributor-concentration risk. Overall, it is healthy but not yet mature enough to warrant a score in the highest band.

Latest 2.15.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All four recent commits came from one contributor, creating concentration risk. The organization-owned repository provides some capacity to hand maintenance off, so this is a caution rather than a severe risk.

Repo commit activitycaution

The repository recorded four commits in the last three months from one active maintainer, showing recent activity but a modest maintenance pace and limited observed capacity.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is neutral rather than positive because it may reflect a quiet project or limited community engagement.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This provides no external adoption support, but popularity is only supporting evidence and the low counts are not independently a severe health issue.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a hygiene gap, though it does not by itself make the package unfit to depend on.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Wingify developers

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^3.0 || ^4.2
—
—
lastguest/murmurhash
Version ^2.1.1
—
—
vwo/vwo-fme-sdk-log-messages
Version ^2.0.0
—
—

Weekly Downloads

Info

Last Published
14 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform