Package Health

smartassert/worker-manager-client

This is a generally healthy, actively released PHP client with a stable major version, a four-year history, regular releases, an unarchived organization-backed repository, tests, CI workflows, and a matching source repository. The main concerns are that commit activity shows no commits or active maintainers in the last 3 months, repository popularity is minimal, no security policy or security-scanning tooling is present, and workflow token permissions are not explicitly constrained; these are meaningful hygiene and maintenance risks but do not outweigh the strong release, repository, and testing evidence.

Latest 16.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitycaution

No commits and no active maintainers are recorded in the last 3 months, which weakens evidence of ongoing development. This is partly offset by the recent repository push and six releases in the last year, but the direct commit signal remains a maintenance caution.

Repo popularitycaution

The repository has 0 stars, 0 forks, and 1 watcher, indicating limited external adoption or visibility. Popularity is supporting evidence rather than a verdict, so this is a modest concern rather than a severe risk.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured. The missing scanning is a repository hygiene gap, though it does not by itself establish that the package is unsafe.

Security policycaution

The repository has no security policy. This reduces vulnerability-reporting transparency and is a genuine repository hygiene gap.

Token permissionscaution

All 3 workflows omit top-level token permissions declarations. Although none declares top-level write access, explicitly limiting permissions would provide stronger CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jon Cram

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
psr/http-factory
Version ^1.0
psr/http-message
Version ^1.0
smartassert/service-client
Version ^8

Weekly Downloads

Info

Last Published
18 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform