Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-29 09:52 UTC

php-soap / psr18-attachments-middleware

Add SWA / MTOM attachments to your SOAP client

PHPMIT★ 2 estrellas⑂ 1 forkdesde ene 2025Ver en GitHub ↗

php-soap/psr18-attachments-middleware tiene un índice de salud de 57 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (67/100) y la más baja, AI Readiness (37/100). Se actualizó por última vez hace 30 días. Una sola persona concentra la mayor parte del trabajo reciente.

57
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

57
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

php-soapOrganización
34 seguidores13 repositorios públicosdesde mar 2021

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Packagistphp-soap/psr18-attachments-middleware0.10.0648410hace 30 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

67Moderado · 22% del índice global
Cómo se puntúa
28.8/36Recencia de push — último push hace 30 días
4.8/36Cadencia de commits — 7/52 semanas con commits
11.5/18Volumen de commits — 18 commits en el último año
6/10OpenSSF Scorecard: Maintained — 8 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 6
Datos de entrada utilizados
commits_last_year18
human_commit_share1
days_since_last_push30
active_weeks_last_year7
Cómo se puntúa
27/27Publica versiones — 10 versiones publicadas
36/36Recencia de las versiones — última versión hace 30 días
19.8/27Cadencia de publicación — una versión cada ~59,8 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count10
latest_release_tag0.10.0
releases_from_tagsno
days_since_latest_release30
mean_days_between_releases59,8
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

45En riesgo · 18% del índice global
Cómo se puntúa
0/60Estrellas — 2 estrellas
0/25Forks — 1 forks
0/15Observadores — 2 observadores
Datos de entrada utilizados
forks1
stars2
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conduct
has_pull_request_template
Cómo se puntúa
50.8/80Descargas mensuales — 6484 descargas/mes en packagist
0/20Dependientes en el registro — 0 paquetes dependen de él
Datos de entrada utilizados
packagesphp-soap/psr18-attachments-middleware
dependents0
ecosystemspackagist
total_downloads49.616
monthly_downloads6484

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

59Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
1.2/22.5Distribución de commits — el principal contribuyente firma el 95% de los commits
2.7/13.5Amplitud de contribuyentes — 2 contribuyentes
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Datos de entrada utilizados
bus_factor1
contributors_sampled2
top_contributor_share0,946
Cómo se puntúa
46.8/46.8Resolución de issues — 100% de issues cerradas
23.5/38.3Aceptación de PR — 8/13 PR decididos fusionados
1.5/15OpenSSF Scorecard: Code-Review — Found 2/15 approved changesets -- score normalized to 1
Datos de entrada utilizados
merged_prs8
open_issues0
closed_issues2
issue_closed_ratio1
closed_unmerged_prs5
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
11.1/25Alcance del propietario — 34 seguidores de php-soap
19/25Trayectoria — 13 repos públicos, cuenta de ~5 años
Datos de entrada utilizados
followers34
owner_typeOrganization
is_verified
owner_loginphp-soap
public_repos13
account_age_days1951
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en packagist
35/35Recencia de publicación — última publicación hace 30 días
20/20Historial de versiones — 10 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesphp-soap/psr18-attachments-middleware
ecosystemspackagist
any_deprecatedno
min_days_since_publish30

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

63Moderado · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 4 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — .php-cs-fixer.dist.php
0/9.6Hooks de pre-commit
0/6.4.editorconfig
14/20OpenSSF Scorecard: CI-Tests — 6 out of 8 merged PRs checked by a CI test -- score normalized to 7
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_config
has_precommit_configno

Documentación

40En riesgo
Cómo se puntúa
30/30README
0/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
0/10Topics
0/10Wiki
Datos de entrada utilizados
topics
has_wikino
homepage
has_readme
has_docs_dirno
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

47En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
1.8/2.5CI-Tests — 6 out of 8 merged PRs checked by a CI test -- score normalized to 7
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0.8/7.5Code-Review — Found 2/15 approved changesets -- score normalized to 1
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
4.5/7.5Maintained — 8 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 6
0/5Packaging — sin datos
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4,7
Excluidos de la puntuación (sin datos o no aplicable): packaging, signed_releases. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

37En riesgo · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
25.9/40Historial de commits legible — 18 de 37 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,486
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
11/11Configuración de lint / formato — .php-cs-fixer.dist.php
0/11Verificación estática de tipos
0/10Entorno reproducible
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 37
5/8Mantenimiento automatizado — automatización de dependencias configurada, no observada en los commits muestreados
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfiles
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
0/45Código verificable por tipos — PHP sin configuración de verificación de tipos
55/55Tamaños de archivo manejables — 0/29 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languagePHP
largest_source_bytes12.016
source_files_sampled29
oversized_source_files0

Datos clave

2estrellas de GitHub
2contribuidores
18commits en los últimos 12 meses
30días desde el último push
10versiones publicadas
1factor bus
0issues abiertas
Packagistecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 4.7 / 10
4.7agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-29 09:51 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
7CI-Tests6 out of 8 merged PRs checked by a CI test -- score normalized to 7
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
1Code-ReviewFound 2/15 approved changesets -- score normalized to 1
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
6Maintained8 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 6
n/dPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 669,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "PHP": 62326
      },
      "pushed_at": "2026-06-29T09:26:30Z",
      "created_at": "2025-01-06T08:09:07Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-27T13:21:32Z",
      "description": "Add SWA / MTOM attachments to your SOAP client",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "PHP",
      "significant_languages": [
        "PHP"
      ]
    },
    "owner": {
      "blog": null,
      "name": "php-soap",
      "type": "Organization",
      "login": "php-soap",
      "company": null,
      "location": null,
      "followers": 34,
      "avatar_url": "https://avatars.githubusercontent.com/u/81407517?v=4",
      "created_at": "2021-03-26T07:07:14Z",
      "is_verified": null,
      "public_repos": 13,
      "account_age_days": 1951
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "0.10.0",
          "kind": "minor",
          "published_at": "2026-06-29T09:08:44Z"
        },
        {
          "tag": "0.9.0",
          "kind": "minor",
          "published_at": "2026-05-27T14:33:32Z"
        },
        {
          "tag": "0.8.0",
          "kind": "minor",
          "published_at": "2026-03-27T13:40:32Z"
        },
        {
          "tag": "0.7.0",
          "kind": "minor",
          "published_at": "2026-03-19T08:40:57Z"
        },
        {
          "tag": "0.6.0",
          "kind": "minor",
          "published_at": "2026-03-11T15:15:07Z"
        },
        {
          "tag": "0.5.0",
          "kind": "minor",
          "published_at": "2025-10-20T11:49:47Z"
        },
        {
          "tag": "0.4.0",
          "kind": "minor",
          "published_at": "2025-05-22T06:41:30Z"
        },
        {
          "tag": "0.3.0",
          "kind": "minor",
          "published_at": "2025-04-22T05:33:40Z"
        },
        {
          "tag": "0.2.0",
          "kind": "minor",
          "published_at": "2025-01-07T13:14:01Z"
        },
        {
          "tag": "0.1.0",
          "kind": "minor",
          "published_at": "2025-01-06T18:41:45Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "d8a4dc763022b52d7d08a65285d73f84d6287ca2",
          "body": "Migrate multipart handling to Psl\\MIME",
          "is_bot": false,
          "headline": "Merge pull request #16 from php-soap/feature/migrate-to-psl-mime",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-06-29T09:07:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78c13bc722138a3d287ab6d2c389dc9cd1dc0289",
          "body": "Calls the php-soap/java-interop reusable workflow so each push and pull request\nverifies this middleware against the Apache WSS4J oracle on PHP 8.4 and 8.5.\n\nClaude-Session: https://claude.ai/code/session_017zRT2TyR9h55bNAHSCNToK",
          "is_bot": false,
          "headline": "Run the cross-stack interop suite in CI",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-06-29T08:46:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7ad7a04fa9b125caf2f3b18b23f2a94a6de83d2",
          "body": "Reads cleaner at call sites: HandleConverter::intoResource($handle) and\nHandleConverter::intoStream($handle).",
          "is_bot": false,
          "headline": "Rename HandleToResource to HandleConverter with intoResource/intoStream",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-06-26T11:31:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cca99cdcedfe31ddd17a0305c900ad21fa8548b3",
          "body": "The src/Mime classes are stream/handle bridges, not MIME logic, so the\nnamespace is renamed to Stream. StreamCopy is renamed to HandleToResource\n(it drains a Psl\\IO read handle into a resource) with clearer method names:\nstream() returns a ResourceStream, resource() returns the raw resource.",
          "is_bot": false,
          "headline": "Rename Mime namespace to Stream and StreamCopy to HandleToResource",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-06-26T11:29:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a354497c0e33020328bf7cd1a09af580bfd32c7",
          "body": "Make both builders memory-bounded to restore the streaming profile of the\nprevious php-http AppendStream-based implementation:\n\n- Add Mime\\StreamCopy: drains a Psl\\IO read handle into a tmpfile-backed\n  ResourceStream in fixed-size chunks (toResourceStream), with toResource\n  transferring ownership \n[…]\ne straight\n  into its ResourceStream, dropping the readAll-to-string round-trip.\n\nPeak memory is now bounded to a single chunk plus disk-backed temp files,\nwhile request/response bodies stay seekable.",
          "is_bot": false,
          "headline": "Stream multipart bodies instead of buffering into strings",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-06-26T11:18:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cf50a4786ae76e9c20234d8c367af10cc738ae06",
          "body": "Replace php-http/multipart-stream-builder and riverline/multipart-parser\nwith Psl\\MIME (parser + builder) plus a small in-repo PSR-7 to Psl\\IO\nstream adapter (StreamReadHandle).\n\n- RequestBuilder builds via Psl\\MIME\\MultiPart\\Related + Part\\Part\n  (raw headers, Content-Transfer-Encoding: binary pres\n[…]\nis behaviour-preserving; existing tests are the spec. One MTOM\nresponse fixture's root-part Content-Type was corrected to quote the 'type'\nparameter, which RFC 2045 requires for values containing '/'.",
          "is_bot": false,
          "headline": "Migrate multipart handling to Psl\\MIME",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-06-26T10:44:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7733705707074becfc91fa8a95cd1ed093b05198",
          "body": "Migrate XopIncludeEncoder to STAB optics",
          "is_bot": false,
          "headline": "Merge pull request #14 from php-soap/feature/reflecta-stab-migration",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-05-27T14:32:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f7779da514040e187137e3c377ac7b576e70ed2",
          "body": "Update XmlEncoder/Iso generics to 4-template STAB form for the new\nveewee/reflecta interfaces. The iso() return declares the honest\nasymmetric shape (Element|non-empty-string accepted on the from\ninput fast path).\n\nComposer wires the local encoding migration branch and local\nreflecta feature/stab-optics via path repositories.",
          "is_bot": false,
          "headline": "Migrate XopIncludeEncoder to STAB optics",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-05-27T14:31:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "716af850c3dfa93e74154d1afbbe57d0ba5a7671",
          "body": "Bump PHP 8.4 minimum, standalone PSL packages, update dependencies",
          "is_bot": false,
          "headline": "Merge pull request #11 from php-soap/feature/php84-minimum",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-03-27T13:39:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccec6a39ad56b433c4fb3c57bb7949465ae0da1b",
          "body": "…, bump dependencies\n\n- Require PHP ~8.4.0 || ~8.5.0 (drop 8.3)\n- Replace php-standard-library/php-standard-library with standalone packages (foundation, regex, result, secure-random, type) ^6.1\n- Bump php-soap/psr18-transport to ^2.0\n- Bump php-soap/encoding to ~0.32\n- Bump php-standard-library/psalm-plugin to ^2.4\n- Remove PHP 8.3 from GitHub Actions matrices\n- Set psalm phpVersion to 8.4",
          "is_bot": false,
          "headline": "Bump PHP 8.4 minimum, replace monolithic PSL with standalone packages…",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-03-27T13:36:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abb24d3aee13cc5653209b919ed354f5ab02f2ae",
          "body": "…ndard-library\n\nReplace azjezz/psl with php-standard-library/php-standard-library",
          "is_bot": false,
          "headline": "Merge pull request #10 from php-soap/feature/replace-psl-with-php-sta…",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-03-19T08:39:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cbf7ac482b58f9868720d81ff08f4b04d49b564b",
          "body": "Ensures all dependency resolution strategies resolve encoding with\nphp-standard-library/php-standard-library instead of azjezz/psl.",
          "is_bot": false,
          "headline": "Bump php-soap/encoding minimum to ~0.28",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-03-19T08:35:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "354bb2635769919a5fab56a03b2a7d40d281645d",
          "body": "Swap to the official fork and add ^6.0 to the version constraint.\n\nRef: phpro/soap-client#604",
          "is_bot": false,
          "headline": "Replace azjezz/psl with php-standard-library/php-standard-library",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-03-19T07:46:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea7bc3b912359e6dc5ae562ca355bcdd8aa391e1",
          "body": "Allow PSL 5.x",
          "is_bot": false,
          "headline": "Merge pull request #9 from php-soap/psl5",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-03-11T15:13:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "028d4719dca689780055934539b0a94ef415dd92",
          "body": null,
          "is_bot": false,
          "headline": "Allow PSL 5.x",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2026-03-11T15:10:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "debc2162c8641b9e873ed31189dbbba7791990a0",
          "body": "Php 85 upgrade",
          "is_bot": false,
          "headline": "Merge pull request #8 from php-soap/php-85-upgrade",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-10-20T11:47:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd83968e02f7c9c94869272310bdad2cc9ab20cd",
          "body": null,
          "is_bot": false,
          "headline": "Fix psalm issues",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-10-20T11:45:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61e1f09f80bc90d22024759a61a2812b16069fb6",
          "body": "- Remove support for PHP 8.2, add support for PHP 8.5\n- Update dependencies to latest compatible versions:\n  - azjezz/psl: Support both ^3.1 and ^4.0 ranges\n  - phpunit/phpunit: Upgraded to ~12.4.0\n  - vimeo/psalm: Upgraded to ~6.13.0\n  - php-cs-fixer/shim: Added ~3.88.0\n  - php-soap packages: Updat\n[…]\nttribute=false\n\nCode upgraded by GitHub Copilot CLI agent.\n\nTests: ✅ 25 tests passing\nStatic analysis: ⚠️ 2 pre-existing psalm errors (unrelated to upgrade)\nCode style: ✅ All files formatted correctly",
          "is_bot": false,
          "headline": "Upgrade project to PHP 8.5",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-10-20T11:42:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6be150c3e9e3e45df9b341fa431ef7049f9506ba",
          "body": "Optional 'start' parameter",
          "is_bot": false,
          "headline": "Merge pull request #7 from aldenw/feat/optional-start",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-05-22T06:40:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61dea98b11d89b022b400b093e9ce5cc67792712",
          "body": null,
          "is_bot": false,
          "headline": "Improve + document code-changes",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-05-22T06:35:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25f4ec6492e2d5c60b46d36052a6bf4ce161fe63",
          "body": null,
          "is_bot": false,
          "headline": "Optional start parameter",
          "author_name": "Alden Weddleton",
          "author_login": "aldenw",
          "committed_at": "2025-05-22T05:28:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3da78f8bfeb7d26d5b325a42c5a87a7208dd7942",
          "body": "Remove http client dependency",
          "is_bot": false,
          "headline": "Merge pull request #5 from aldenw/feat/remove-http-client-dependency",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-04-22T05:32:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76ba798bf803ca8cba1f5f09d1b3394e6cd3a4ce",
          "body": null,
          "is_bot": false,
          "headline": "Remove http client dependency",
          "author_name": "Alden Weddleton",
          "author_login": "aldenw",
          "committed_at": "2025-04-21T20:37:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6948977c828d445b9c2a3e44a4aff666ca0406de",
          "body": null,
          "is_bot": false,
          "headline": "Broaden deps",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-02-13T05:36:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc1a67899d6dc45cca14965f740cbae75dd1f1ff",
          "body": "…g Content-Id",
          "is_bot": false,
          "headline": "Pass SOAP 1.2 Action to XOP and use a valid cid identifier as startin…",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-07T13:11:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c71fe9c8d827dd0b4dba24e196dab21762eb5e0f",
          "body": null,
          "is_bot": false,
          "headline": "Use CID compliant hrefs in XOP Include encoder",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-07T12:46:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eaed608feeabc54e2609290e4a89bff4d7c9483d",
          "body": null,
          "is_bot": false,
          "headline": "Improve docs",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-07T07:22:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5aca7b660777ddae6f594d035df52fa7c52ea448",
          "body": null,
          "is_bot": false,
          "headline": "Better code example",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-07T07:17:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4855704c657732caddcc9c7b10a88150d6f2d571",
          "body": null,
          "is_bot": false,
          "headline": "Add missing test",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-06T19:03:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b818d00f1b31cebbcd76767b74e72c7ba2689782",
          "body": null,
          "is_bot": false,
          "headline": "Add various tests",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-06T18:39:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0bb979750845c556f1f722a4fd2e4a45efdff68",
          "body": null,
          "is_bot": false,
          "headline": "Add github workflows",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-06T17:05:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb37a8afd332e3786390a064cc844780536ed0ff",
          "body": null,
          "is_bot": false,
          "headline": "Rename namespaces",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-06T17:05:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb4f7c8b11b11803ec75dfdd6ed6e484f96385e4",
          "body": null,
          "is_bot": false,
          "headline": "Improve API",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-06T16:55:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2494aaf21536c4609aef8d88b7f9c974a91fbe5c",
          "body": null,
          "is_bot": false,
          "headline": "Add QA",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-06T09:06:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df6683ce01b20ff58f2771555f78fabcd2752288",
          "body": null,
          "is_bot": false,
          "headline": "Improve docs",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-06T08:24:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60160f29e58a691b4c7c06995173357aff1594fa",
          "body": null,
          "is_bot": false,
          "headline": "API improvements",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-06T08:23:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc17494d3c24221f4387f3b3497e2b51d7fe8ff3",
          "body": null,
          "is_bot": false,
          "headline": "Initial version",
          "author_name": "Toon Verwerft",
          "author_login": "veewee",
          "committed_at": "2025-01-06T08:13:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 10,
      "commits_last_year": 18,
      "latest_release_at": "2026-06-29T09:08:44Z",
      "latest_release_tag": "0.10.0",
      "releases_from_tags": false,
      "days_since_last_push": 30,
      "active_weeks_last_year": 7,
      "days_since_latest_release": 30,
      "mean_days_between_releases": 59.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "php-soap/psr18-attachments-middleware",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/php-soap/psr18-attachments-middleware",
          "is_deprecated": false,
          "latest_version": "0.10.0",
          "repository_url": "https://github.com/php-soap/psr18-attachments-middleware",
          "versions_count": 10,
          "total_downloads": 49616,
          "dependents_count": 0,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 6484,
          "first_published_at": null,
          "latest_published_at": "2026-06-29T09:07:33Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 30
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 2,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2025-04-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 12016,
      "source_files_sampled": 29,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "composer.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "packagist"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 8,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 2,
        "closed_unmerged_prs": 5
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "veewee",
          "commits": 35,
          "avatar_url": "https://avatars.githubusercontent.com/u/1618158?v=4"
        },
        {
          "type": "User",
          "login": "aldenw",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/4245644?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.946
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "analyzers.yaml",
        "code-style.yaml",
        "interop.yml",
        "tests.yaml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        ".php-cs-fixer.dist.php"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 7,
            "reason": "6 out of 8 merged PRs checked by a CI test -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 1,
            "reason": "Found 2/15 approved changesets -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 6,
            "reason": "8 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "d8a4dc763022b52d7d08a65285d73f84d6287ca2",
        "ran_at": "2026-07-29T09:51:50Z",
        "aggregate_score": 4.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-29T04:10:19Z",
      "oldest_open_prs": [
        {
          "number": 15,
          "created_at": "2026-05-28T04:27:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-06-29T09:07:33Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/php-soap/psr18-attachments-middleware",
    "host": "github.com",
    "name": "psr18-attachments-middleware",
    "owner": "php-soap"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 57,
      "inputs": {
        "security": 47,
        "vitality": 67,
        "community": 45,
        "governance": 59,
        "engineering": 63
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 67,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 51,
            "inputs": {
              "commits_last_year": 18,
              "human_commit_share": 1,
              "days_since_last_push": 30,
              "active_weeks_last_year": 7
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 30 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "7/52 weeks with commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "18 commits in the last year",
                "points": 11.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 18
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "8 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 92,
            "inputs": {
              "releases_count": 10,
              "latest_release_tag": "0.10.0",
              "releases_from_tags": false,
              "days_since_latest_release": 30,
              "mean_days_between_releases": 59.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "10 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 30 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~59.8 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 59.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 30,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 30 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 45,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 2,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 51,
            "inputs": {
              "packages": [
                "php-soap/psr18-attachments-middleware"
              ],
              "dependents": 0,
              "ecosystems": "packagist",
              "total_downloads": 49616,
              "monthly_downloads": 6484
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "6,484 downloads/month across packagist",
                "points": 50.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 6484,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "0 packages depend on it",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 59,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 19,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.946
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 95% of commits",
                "points": 1.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 95
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "merged_prs": 8,
              "open_issues": 0,
              "closed_issues": 2,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 5
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "8/13 decided PRs merged",
                "points": 23.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 8,
                      "decided": 13
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 2/15 approved changesets -- score normalized to 1",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "followers": 34,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "php-soap",
              "public_repos": 13,
              "account_age_days": 1951
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "34 followers of php-soap",
                "points": 11.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 34,
                      "login": "php-soap"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "13 public repos, account ~5 yr old",
                "points": 19,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 13
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "php-soap/psr18-attachments-middleware"
              ],
              "ecosystems": "packagist",
              "any_deprecated": false,
              "min_days_since_publish": 30
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 30 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "10 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 63,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".php-cs-fixer.dist.php",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".php-cs-fixer.dist.php"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "6 out of 8 merged PRs checked by a CI test -- score normalized to 7",
                "points": 14,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "at_risk",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 47,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 47,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "6 out of 8 merged PRs checked by a CI test -- score normalized to 7",
                "points": 1.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 2/15 approved changesets -- score normalized to 1",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "8 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 6",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 37,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 26,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.486,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "18 of 37 human commits state their intent (structured subject or explanatory body)",
                "points": 25.9,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 18,
                      "sampled": 37
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".php-cs-fixer.dist.php",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".php-cs-fixer.dist.php"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 37",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 37
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 12016,
              "source_files_sampled": 29,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/29 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 29,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T09:52:06.327081Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/php-soap/psr18-attachments-middleware.svg",
  "full_name": "php-soap/psr18-attachments-middleware",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasPackagist.