Package Health

snicco/session

The source includes a real test suite, matching repository, license, and no install-time scripts. There is no security policy, and its sole workflow uses an unpinned action, leaving maintenance and build controls thin.

Latest v2.0.0-beta.9PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has had no release in about two years, despite 33 releases overall; this is strong evidence that maintenance has slowed or stopped.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the prolonged maintenance gap.

Security policycaution

The repository has no security policy. This is a transparency and response-process gap for a session library, although it is not evidence of a security defect.

Version stabilitycaution

The assessed release is a beta, and 45% of recent releases were prereleases, so API or behavior changes remain more likely than for a mature stable release.

Workflow auditcaution

The only workflow is fully analyzed and has no reported findings, but its one action use is unpinned. The pull_request_target trigger is acceptable here because no untrusted checkout or script injection was found.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Calvin Alkan

Direct Dependencies

DependencyLast ReleaseScore
snicco/str-arr
Version ^2.0
snicco/testable-clock
Version ^2.0
paragonie/constant_time_encoding
Version ^2.4

Weekly Downloads

Info

Last Published
2 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform