Package Health

abhisingh159/inflow-cloud-php-sdk

This is a usable but immature package with a clear MIT license, a focused dependency profile, a non-deprecated release, and a repository that matches the package and was recently pushed. However, it is only 101 days old, remains on the unstable 0.x line, has no tests or changelog, has no security scanning or security policy, and shows zero commits or active maintainers over the last three months despite recent publication activity. The single-user ownership and lack of repository popularity provide little evidence of maintenance resilience, so adoption is reasonable for bounded use but carries meaningful continuity and quality risk.

Latest v0.1.3PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitydanger

The repository reports zero commits and zero active maintainers during the last three months. This is a significant maintenance-risk signal, even though the repository was pushed recently and the package has recent releases.

Maintainerscaution

Only one registry account has publish access, which creates a limited publishing and continuity base. The repository is user-owned rather than organization-backed, so there is no provided organizational evidence to offset that limitation.

Package file treecaution

The small, coherent 16-file tree is understandable and focused on SDK source and resources, but it contains no tests or other supporting project files, limiting evidence of engineering maturity.

Package scaffoldingcaution

A substantial README documents requirements, configuration, and usage, but neither the artifact nor repository contains tests or a changelog. For an SDK, the absence of tests is a meaningful quality and maintenance gap.

Project backingcaution

The package is backed by a matching repository owned by the same individual user, which establishes source continuity but offers less institutional backing and redundancy than an organization-owned project.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

abhisingh159

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.8
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform