Package Health

buerxiaojie/laravel-aliyunmns

The seven-file artifact is easy to inspect and the documented setup is concise. No security policy and negligible repository activity leave little evidence of ongoing support, making future compatibility uncertain.

Latest 1.1.2PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has only two releases, with the latest published on February 23, 2018 and none in the past 12 months. That long period without releases is substantial abandonment evidence, despite the stable 1.1.2 version.

Project backingcaution

The repository is owned by an individual account rather than an organization, so there is no organizational backing shown by this signal. That matters more alongside the absence of recent activity.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 0 watchers. Popularity is not required for a healthy package, but these very low figures provide little supporting evidence of community use or review.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem. No security scanning tools are reported, providing no additional evidence of ongoing security maintenance.

Security policycaution

The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, although it is less serious than the lack of recent releases.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

buer

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version >=5.3
—
—
wtwei/aliyun-dysms
Version 0.2.*
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform