Package Health

stonewaves/credstash

The package is clearly licensed and documented, with a stable artifact and no install-time scripts. Its source remains unarchived and identifies the package, but it lacks a security policy and automated security scanning.

Latest 1.0.4PackagistPackagist

46%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was in November 2019, with no releases in the following six years and ten months. This is strong evidence of abandonment risk for a library handling AWS-backed secrets.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and indicating no current maintenance capacity.

Repo toolingcaution

Composer is used for the build, but no security-scanning tools are configured. The missing scanning is a modest maintenance and security-hygiene concern, not evidence that the package is malicious.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a genuine transparency gap for a package that manages secrets.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Carson Full
StoneWaves

Direct Dependencies

DependencyLast ReleaseScore
aws/aws-sdk-php
Version 3.121.1
—
—
webmozart/path-util
Version ^2.3
—
—
symfony/polyfill-php56
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform