Package Health

boson-php/pasm

The MIT license, repository tests, and organization backing improve transparency and reduce adoption friction. Unpinned workflow actions and no security policy leave avoidable maintenance hygiene gaps.

Latest 0.19.5PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, despite the package having recent release history; this is a meaningful maintenance concern.

Security policycaution

The repository has no security policy. This does not show an active security problem, but it reduces transparency for reporting and handling vulnerabilities.

Version stabilitycaution

Version 0.19.5 is not a prerelease, and recent releases contain no prerelease versions, but the package remains below major version 1, so compatibility expectations are somewhat less mature.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous audit findings or broad write permissions, but all 4 referenced actions are unpinned, leaving avoidable build-integrity risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kirill Nesmeyanov

Direct Dependencies

DependencyLast ReleaseScore
ffi/env
Version ^1.0
boson-php/weak-types
Version ^0.19

Weekly Downloads

Info

Last Published
11 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform