Package Health

amphp/aerys-session

The repository remains maintained enough to show tests, security tooling, and a recent release, but activity has stopped in the last three months. The workflow uses five unpinned actions, and the repository does not explicitly identify this package; use the named replacement for new work.

Latest v3.0.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Registry deprecationcaution

Packagist marks the entire package as abandoned and names amphp/http-server-session as its replacement. The linked repository is active and the replacement provides a clear migration path, so this is a significant caution rather than an abandonment verdict.

Release historycaution

The package has existed for over 10 years with 20 releases, but only one release appeared in the last 12 months and the latest release is about 8 months old. Its long history helps, while the slower recent cadence raises maintenance concern.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last 3 months. This is concerning alongside the package's abandonment status, although a release was published about 8 months ago.

Repo package mentioncaution

The repository name does not match amphp/aerys-session and its README does not mention that package name. The repository clearly documents the related http-server-session project, but the mismatch still weakens release-to-source transparency.

Workflow auditcaution

The only workflow was fully analyzed with no high-confidence findings or untrusted checkout paths, but all 5 action references are unpinned. That leaves avoidable build-integrity exposure while remaining a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aaron Piotrowski
Bob Weinand
Niklas Keller

Direct Dependencies

DependencyLast ReleaseScore
amphp/amp
Version ^3
amphp/http
Version ^2
amphp/sync
Version ^2
amphp/cache
Version ^2
amphp/http-server
Version ^3

Weekly Downloads

Info

Last Published
8 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform