Package Health

sirix/inertia-psr15

InertiaJS server-side adapter for PSR-7 and PSR-15 applications

Latest 3.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

The manifest declares BSD-3-Clause, while the artifact license file is recognised as MIT; this mismatch creates avoidable licensing uncertainty despite a license file being present.

Repo commit activitycaution

No commits and no active maintainers were recorded during the last three months. The recent release partly offsets this because it was published on the same day as the last repository push, but ongoing maintenance is not yet demonstrated.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool is configured, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy. This does not show a security defect, but it weakens the project's documented process for handling vulnerabilities.

Workflow auditcaution

The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers or audit findings. However, all 4 of its action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Cherif BOUCHELAGHEM
Sirix

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^1.0 || ^2.0
—
—
psr/http-factory
Version ^1.1
—
—
fig/http-message-util
Version ^1.1
—
—
sirix/container-resolver
Version ^1.0
—
—
psr/http-server-middleware
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform