Package Health

aws/aws-php-sns-message-validator

This is a mature, actively published AWS-owned package with over 11 years of history, a stable release, a current non-archived repository, matching package references, tests, licensing, and a small focused dependency footprint. The main concern is that the repository recorded no commits or active maintainers in the last 3 months, although a release was published recently and two pull requests were merged during the last month, which provides partial evidence of ongoing maintenance. CI has no detected dangerous workflow patterns and includes a security policy, but security scanning is absent and some workflow permission declarations are broad or omitted. Overall, the package appears suitable to depend on, with routine maintenance and CI-hygiene caveats.

Latest 1.10.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo commit activitycaution

No commits and no active maintainers were recorded in the last 3 months, which is a meaningful maintenance concern. However, the recent release, recent repository push, and two merged pull requests partly compensate for the apparent short-term commit lull.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a transparency and preventive-hygiene gap, though it is not evidence that the package is unsafe.

Token permissionscaution

Two workflows omit top-level permissions and one workflow declares top-level write access, while only one is explicitly read-only. This weakens least-privilege transparency and warrants CI-hygiene caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Amazon Web Services

Direct Dependencies

DependencyLast ReleaseScore
psr/http-message
Version ^2.0

Weekly Downloads

Info

Last Published
17 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform