Package Health

async-aws/step-functions

This is a healthy, established release with a stable 1.x version, 17 releases over roughly 5 years, a release as recently as the assessment date, and no registry deprecation. The package is backed by an active organization-owned repository that is not archived, has matching package identity, repository tests, changelog, CI workflows, and two active contributors with balanced recent commit activity. Its small runtime dependency set and absence of install-time scripts further reduce operational risk. The main reservations are that repository security scanning is not configured, the security policy is absent, and workflow token permissions are not explicitly constrained; these are transparency and hardening gaps rather than evidence of abandonment, especially since the analyzed workflows show no dangerous patterns.

Latest 1.7.2PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo issue activitycaution

No new issues or pull requests were recorded in the last month, and issue totals are unavailable. This limits evidence of community interaction, but does not outweigh the recent release and commit activity.

Repo popularitycaution

The repository has zero stars and forks and only two watchers, which provides little external popularity evidence; this is a supporting weakness, not a health verdict, because active release and commit signals are present.

Repo toolingcaution

The repository uses Make and Composer, but no security scanning tools are configured. Build tooling is present, while the missing security automation is a genuine hardening gap.

Security policycaution

No repository security policy was found, reducing transparency around vulnerability reporting and response expectations.

Token permissionscaution

Both workflows lack top-level token permissions declarations. Although no workflow has explicit top-level write permissions, the absence of least-privilege declarations is a workflow hardening gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
async-aws/core
Version ^1.9
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform