Package Health

zero-to-prod/spapi-lwa

Recent release and commit activity are absent, while the workflows use seven unpinned actions and contain high-confidence template-injection findings. The package is documented, licensed, tested in the repository, and not deprecated or archived.

Latest v4.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Dependency profilecaution

Seven runtime dependencies, including three project-local packages and required PHP extensions, create a moderate dependency surface that is relevant to maintenance but not excessive for this package.

Project backingcaution

The registry namespace and repository are owned by the same individual account rather than an organization, so the project has a narrow visible backing structure.

Release historycaution

The package has 20 releases over 603 days, but none in the last 12 months; that weakens confidence in ongoing maintenance despite its earlier release history.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance has gone quiet.

Repo issue activitycaution

There are no new or closed issues in the last month and no merged pull requests, although two pull requests remain open; this is limited evidence of current project activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

David Smith

Direct Dependencies

DependencyLast ReleaseScore
zero-to-prod/factory
Version ^0.1.0
—
—
zero-to-prod/container
Version ^0.1.0
—
—
zero-to-prod/curl-helper
Version ^1.0
—
—
zero-to-prod/package-helper
Version ^1.1.3
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform