Package Health

sarcio/shim

Clear documentation, release notes, organization backing, and a small runtime dependency surface improve its initial transparency. The license mismatch, absent security policy, and entirely unpinned workflow actions leave important trust and maintenance gaps for a new pre-1.0 release.

Latest v0.2.0PackagistPackagist

63%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The manifest declares BUSL-1.1 while the artifact license file is detected as Apache-2.0; the mismatch creates legal and provenance ambiguity despite both the artifact and repository containing license files.

Release historycaution

This is the package's first release, published today, so there is no release track record yet. That limits evidence of maintenance maturity but does not indicate abandonment by itself.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected. That is a modest transparency and maintenance gap for a package that integrates into application request handling.

Security policycaution

The repository has no security policy. For a package that can apply server-side fixes and alter application request behavior, the absence of published vulnerability-reporting guidance is a meaningful transparency gap.

Version stabilitycaution

Version v0.2.0 is pre-1.0, so its API and behavior may still change. It is not marked as a prerelease, which partly offsets the stability concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dayne Mentier

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
15 hours ago
Created
15 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform