Package Health

zitadel/client

This release appears suitable to depend on, with strong transparency and organizational backing: it is actively released, not deprecated or archived, has a matching repository that mentions the package, maintains tests and a substantial source tree, and uses build and security tooling. The main reservations are that the project describes itself as incubating, has no changelog, has modest repository popularity, and only four commits in the last three months, although activity is distributed across three contributors and recent pull requests have been merged. Overall, this is a healthy but still relatively young package rather than a deeply mature dependency.

Latest 4.1.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

A substantial README and tests are present in both the artifact/repository context, and GitHub Releases provide some release documentation; the absence of a changelog is therefore a minor gap. The README's explicit incubating-stage notice indicates evolving APIs and reduces maturity somewhat.

Repo commit activitycaution

Four commits from three active maintainers in the last three months show ongoing maintenance, though the volume is modest for a young SDK and warrants some caution about development pace.

Repo popularitycaution

Five stars and two forks indicate limited external adoption, which lowers ecosystem evidence but is only a supporting signal and does not outweigh the active organizational backing and release history.

Token permissionscaution

Ten workflows declare read-only permissions, while two omit top-level permissions and two require write access for pipeline or release operations. This is a minor workflow-hygiene concern, not a demonstrated severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Zitadel

Direct Dependencies

DependencyLast ReleaseScore
league/uri
Version ^7.5
—
—
guzzlehttp/psr7
Version ^1.7 || ^2.0
—
—
firebase/php-jwt
Version ^7.0.0
—
—
guzzlehttp/guzzle
Version ^7.3
—
—
league/oauth2-client
Version ^2.8
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform