Package Health

workbuddy/openapi

This is a usable but very immature release: it is only one day old, has a single v0.1.0 release, and shows no commits or active maintainers in the last three months, so maintenance continuity is not yet demonstrated. The package is nevertheless transparent and reasonably structured, with an MIT license and license file, a substantial README, repository tests, Composer-based tooling, no install-time scripts, a non-archived repository, and no detected dangerous workflow patterns. The absence of security scanning and a security policy, together with unspecified workflow token permissions, adds operational caution. Adoption may be reasonable for evaluation or controlled use, but the release should be monitored closely and not treated as a mature dependency.

Latest v0.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Project backingcaution

The repository is owned by an individual user rather than an organization, so the project has a limited visible backing structure and likely depends on a single owner.

Release historycaution

The package is only 1 day old and has exactly one release, so there is no observed release track or history demonstrating sustained maintenance.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months; because the project is only 1 day old, this is partly explained by its novelty, but it still leaves maintenance capacity unproven.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is not a health verdict for a new or specialized package, but it provides no supporting evidence of community adoption.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving security-process coverage unestablished.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

jaguarjack

Direct Dependencies

DependencyLast ReleaseScore
symfony/http-client
Version ^6.4

Weekly Downloads

Info

Last Published
17 days ago
Created
17 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform