Package Health

webware/messagebus-event

The repository is actively developed and provides tests, documentation, and release notes. Its beta status, single active contributor, and workflow credential-sharing finding add adoption risk for a young package.

Latest 2.0.0-beta.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Maintainerscaution

Only one registry maintainer is listed, which is a limited publishing base; the organization-owned repository provides some backing but does not remove the single-person operational risk shown by the activity data.

Release historycaution

The package is only 41 days old with two releases and a median interval of about 9 days, so its maintenance record is still short rather than established.

Repo bus factorcaution

One contributor made all recorded commits in the last three months. Organization backing helps with handoff potential, but no second active contributor is shown to reduce current concentration.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.

Version stabilitycaution

Version 2.0.0-beta.1 is explicitly a prerelease, which signals that the API may still change and makes it less suitable for an unattended dependency choice.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joey (aka Tyrsson) Smith

Direct Dependencies

DependencyLast ReleaseScore
webware/message-bus
Version 2.0.x-dev
webware/webware-psl-type
Version ^0.1.x-dev
php-standard-library/type
Version ^6.2
phly/phly-event-dispatcher
Version ^1.5.0
laminas/laminas-servicemanager
Version ^4.0.0

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform