Package Health

phpstreamserver/scheduler

This release appears usable and actively maintained, with 14 releases over 642 days, five releases in the last 12 months, a repository that is not archived, and 38 commits in the last three months. The main concerns are concentrated maintenance in a single active contributor, no tests or changelog in either the artifact or repository, no security scanning or security policy, and a pull-request-target workflow without top-level token permissions. Organization backing and the package/repository name and README alignment provide some mitigation, but the package remains more dependent on one maintainer and has weaker verification and security-process transparency than a highly mature dependency.

Latest v0.10.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target, which can be security-sensitive even though no untrusted checkout or script injection was detected. This warrants review rather than indicating a severe issue on its own.

Dependency profilecaution

Seven runtime dependencies, including platform extensions and the event-loop/runtime stack, create a meaningful dependency surface for a scheduler library but are proportionate to its functionality.

Package scaffoldingcaution

The package includes a README, but neither the artifact nor repository contains tests or a changelog. For a runtime scheduler library, the absence of repository tests is a genuine maintenance and regression-risk gap.

Repo bus factorcaution

All 38 recent commits came from one contributor, creating a clear continuity and bus-factor concern. The organization-owned repository provides some capacity for handoff, but no second active contributor is evidenced.

Repo issue activitycaution

There were no new or closed issues and no pull requests in the last month. This is ambiguous because it may reflect a quiet project, but it provides little evidence of broader maintenance participation.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Anton Zenkov

Direct Dependencies

DependencyLast ReleaseScore
amphp/amp
Version ^3.0
revolt/event-loop
Version ^1.0
phpstreamserver/core
Version ^0.10
dragonmantank/cron-expression
Version ^3.4

Weekly Downloads

Info

Last Published
13 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform