Package Health

kinetis/aws-sigv4

Usable with caveats: it is a very young package with all recent commits coming from one contributor and no repository security policy. The organization-backed repository has matching package references, tests, active recent commits, and no install-time scripts, which lowers the adoption risk.

Latest v1.3.2PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

Nine runtime dependencies, including multiple HTTP client implementations and related libraries, increase dependency surface and upgrade coordination compared with a narrowly self-contained package.

Release historycaution

The package is only 20 days old, although it has six releases with a median interval of about 2.6 days; this shows active iteration but not yet long-term maintenance maturity.

Repo bus factorcaution

One contributor made all eight commits in the last three months, creating a real continuity risk. Organization backing provides some capacity for handoff, but no second active contributor is shown.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected; this is a transparency and maintenance gap rather than evidence that the release is unsafe.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alon Noy

Direct Dependencies

DependencyLast ReleaseScore
nyholm/psr7
Version ^1.8.2
—
—
async-aws/core
Version ^1.29.2
—
—
psr/http-client
Version ^1.0.3
—
—
psr/http-message
Version ^2.0
—
—
amphp/http-client
Version ^5.3.6
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform