Package Health

async-aws/ses

This is a healthy, mature release with a six-year history, regular recent publishing, stable versioning, an active non-archived organization-backed repository, and four active contributors over the last three months. The package is licensed, has a changelog, repository tests, restrained runtime dependencies, no install-time lifecycle scripts, and no detected dangerous workflow patterns. The main concerns are that repository security scanning is absent, both workflows omit top-level token permissions, and no security policy is published; these are transparency and CI-hardening gaps rather than evidence of abandonment. Several other health dimensions were not collected, so the assessment is strong but not fully comprehensive.

Latest 1.17.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo toolingcaution

Make and Composer build tooling are present, but no security-scanning tools were detected. The build setup is positive, while the missing security automation is a modest hygiene gap.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting guidance undocumented. This is a transparency gap, though it is not evidence that the package is unmaintained.

Token permissionscaution

Both workflows omit top-level token permissions, so least-privilege CI intent is not explicitly declared. No workflow has top-level write permissions, which limits the severity of this gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
async-aws/core
Version ^1.9

Weekly Downloads

Info

Last Published
14 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform