Package Health

pusher/pusher-php-server

The project has a long release history, a current stable release, and an organization behind it. Tests, release notes, and recent publishing support adoption, though recent activity is concentrated in one contributor.

Latest 7.3.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitycaution

Only 1 commit from 1 active maintainer was recorded in the last 3 months, indicating limited recent activity. The recent 7.3.0 release and organization backing provide some compensation.

Security policycaution

The repository has no published security policy, reducing transparency about vulnerability reporting and response. This is a process gap, not evidence that the release is unsafe.

Workflow auditcaution

The audit found two high-confidence template-injection findings in the release workflow and all 6 of 6 action references are unpinned. No untrusted checkout or privileged trigger was reported, so these are meaningful hygiene concerns rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
guzzlehttp/psr7
Version ^2.6.3 || ^3.0
psr/http-client
Version ^1.0
guzzlehttp/guzzle
Version ^7.8.2 || ^8.0
guzzlehttp/promises
Version ^2.0.3 || ^3.0

Weekly Downloads

Info

Last Published
1 month ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform