Package Health

serendipity_hq/bundle-aws-ses-monitor

All workflow action references are unpinned, and one uses an archived action. The repository has no security policy, though it has tests, a README, and security scanning tools.

Latest 2.1.0PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

Composer post-install and post-update scripts run during dependency operations, adding supply-chain and installation complexity that developers should account for.

Release historycaution

The package has 38 releases since July 2020, but none in the last 12 months; this is meaningful evidence of slowing maintenance for a dependency.

Repo commit activitycaution

There were no commits from any active maintainer in the last three months, which is a direct maintenance concern despite the repository's recent push timestamp.

Security policycaution

No repository security policy is provided, reducing transparency about vulnerability reporting and response expectations.

Workflow auditcaution

All 29 analyzed action references are unpinned, and the audit found one high-confidence medium-severity use of an archived action. No untrusted checkout, script injection, or broad top-level write permissions were found.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Adamo Aerendir Crespi

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^2.5 || ^3.0
—
—
symfony/yaml
Version ~4.4|~5.4|~6.0|~7.0
—
—
aws/aws-sdk-php
Version ^3.39.0
—
—
doctrine/common
Version ^2.4 || ^3.0
—
—
symfony/http-kernel
Version ~4.4|~5.4|~6.0|~7.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform