Package Health

wsdltophp/wsdlhandler

Strong tests, documentation, release notes, and an organization-backed repository support dependable maintenance practices. The workflows use all 8 actions without pinning and reference archived actions, while the lack of recent commits adds ongoing maintenance risk.

Latest 1.0.7PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has 8 releases since January 2021, but none in the last 12 months and the latest release was about 20 months ago. This is meaningful evidence of slowing maintenance, despite a previously regular median release interval of about 62 days.

Repo commit activitycaution

There were no commits and no active maintainers in the last 3 months. Combined with no releases in the last year, this lowers confidence in ongoing maintenance.

Security policycaution

No security policy is present in the repository. This is a modest transparency gap for reporting vulnerabilities, but it is not by itself evidence of abandonment.

Workflow auditcaution

All 8 analyzed action references are unpinned, and both workflows use archived actions with high-confidence medium-severity findings. There are no untrusted checkouts, script injections, or top-level write permissions, which limits the impact to workflow hygiene rather than a severe supply-chain concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mikaël DELSOL

Direct Dependencies

DependencyLast ReleaseScore
wsdltophp/domhandler
Version ~2.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform