Package Health

black-bits/bestcdn-sdk-php

The package includes a useful README and tests, with an MIT declaration and no install-time scripts. Its work-in-progress status, absent security policy, and inactive project make adoption a poor choice.

Latest 0.1.9PackagistPackagist

12%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.

Release historydanger

The last release was about 8 years ago, and there were no releases in the past 12 months. This strongly indicates abandonment rather than an actively maintained release line.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the past 3 months, consistent with the long release gap. The organization backing does not compensate for the absence of observed maintenance.

Security policycaution

The linked repository has no security policy. For an SDK handling CDN credentials and file operations, this reduces transparency about vulnerability reporting and response.

Version stabilitycaution

Version 0.1.9 is not a stable major release, and the README describes the project as unstable and work in progress. That adds compatibility and maturity risk on top of the abandonment evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Oliver Heck
Andreas Przywara

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^6.3
—
—
illuminate/support
Version 5.1.*|5.2.*|5.3.*|5.4.*|5.5.*|5.6.*|5.7.*
—
—
illuminate/contracts
Version ^5.5
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform