Package Health

hermesihq/hermesi

Documentation and packaging are solid, and the organization-backed repository is active in setup. The release is too new to establish maintenance capacity, while workflow references are not pinned and no security policy is present.

Latest v0.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

This is the package's first release, published today, so there is no release history or cadence yet; that limits evidence of sustained maintenance but is expected for a new project.

Repo commit activitycaution

There were no commits or active maintainers in the last 3 months. Because the release is brand new, this is weak evidence rather than proof of abandonment, but it leaves maintenance capacity unestablished.

Security policycaution

The repository has no security policy. That reduces vulnerability-reporting transparency for a package that handles HTTP requests, authentication, tokens, and event delivery.

Version stabilitycaution

v0.1.0 is not a stable major release, which signals an early API and limited maturity; it is not marked as a prerelease.

Workflow auditcaution

The single workflow was fully analyzed and uses read-only permissions with no high- or medium-confidence findings, but all 6 of 6 action references are unpinned, weakening build reproducibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/http-message
Version ^1.1 || ^2.0
—
—
php-http/discovery
Version ^1.19
—
—
psr/http-client-implementation
Version 1.0
—
—

Weekly Downloads

Info

Last Published
18 hours ago
Created
18 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform