Package Health

thesis/nats

This release is usable and has solid transparency: it is MIT-licensed, non-deprecated, backed by an organization-owned repository that matches the package, includes a substantial README and changelog, and has repository tests even though tests are not packaged. However, the package is relatively young, remains on the 0.x major line, and the repository recorded no commits or active maintainers in the last 3 months, which is the main abandonment and maintenance concern. The absence of a security policy and explicit workflow token permissions adds smaller hygiene risks, while the workflow analysis found no dangerous patterns. Overall, adoptable with caution, particularly if ongoing maintenance is important.

Latest 0.4.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitydanger

There were zero commits and zero active maintainers in the last 3 months, a significant maintenance and abandonment concern despite the recent repository push and release activity.

Dependency profilecaution

The package has 11 runtime dependencies, including several related asynchronous and Thesis components; this is a meaningful dependency surface but appears consistent with a full-featured NATS driver rather than an unexplained excess.

Repo issue activitycaution

One pull request was merged in the last month, but there were no new or closed issues and only five open issues, indicating limited recent issue-management activity.

Repo toolingcaution

Composer and Make are used as build tools, but no security-scanning tools were detected; the missing scanning coverage is a modest repository hygiene gap.

Security policycaution

No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Valentin Udaltsov
kafkiansky
Thesis Team

Direct Dependencies

DependencyLast ReleaseScore
amphp/amp
Version ^3.1.1
—
—
amphp/parser
Version ^1.1
—
—
amphp/socket
Version ^2.3.1
—
—
cuyz/valinor
Version ^1.15 || ^2.3
—
—
amphp/pipeline
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform