Package Health

wyi/dtm-client

The MIT license, substantial README, matching repository, and repository tests improve transparency. Unpinned workflow actions and an archived action add maintenance risk, while no security policy leaves oversight unclear.

Latest v0.2.2PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has had only 5 releases, all ending in July 2022, with no releases in the last 12 months despite being over four years old. This is strong evidence of abandonment risk.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance capacity.

Repo popularitycaution

The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these figures provide little indication of a broad support base.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented. This is a transparency gap, though it does not by itself show unsafe code.

Workflow auditcaution

Both workflows were analyzed without untrusted triggers or script injection, but all 4 action references are unpinned and one high-confidence medium-severity finding uses an archived action. These weaken build reproducibility and maintenance hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
hyperf/guzzle
Version ^2.2|^3.0
—
—
hyperf/context
Version ^2.2|^3.0
—
—
psr/http-server-middleware
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform