Usable with caveats: this is a young, clearly documented package with recent releases and a coherent source repository. Adoption depends heavily on one maintainer, with no security policy or automated security scanning and only modest project activity so far.
67%
Total Score
67
100
83
75
Only one account has registry publish access. Because the repository is user-owned rather than organization-owned, this represents a genuine continuity concern, although actual repository activity provides some compensation.
The package is only 88 days old, with three releases and a median interval of about 21 days. That shows useful early iteration, but there is not yet enough history to establish long-term maintenance.
One contributor made all six commits in the last three months, creating a high single-maintainer dependency. No organization backing is present to provide an obvious handoff path.
The repository has four stars and one fork, so there is little external adoption evidence. Popularity is supporting evidence rather than a requirement, but this leaves the package's real-world validation unclear.
Composer is used as a build tool, but no security-scanning tools are configured. The absence of scanning is a transparency and maintenance gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nativephp/mobile Version ^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.