Package Health

cmslz/wechat-videoid

The project has a single maintainer, one star, no tests, and no security policy. Its substantial source tree, stable version, release notes, and non-archived repository provide some support, but the missing license and stalled releases remain significant concerns.

Latest v1.0.10PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Licensedanger

No license declaration or license file was found in the package or repository, leaving the terms for using and redistributing this SDK unclear.

Maintainerscaution

Only one registry maintainer is listed. The linked repository is owned by the same individual, so there is no visible broader maintainer base to provide continuity.

Release historycaution

The package has eight releases since July 2024, but none in the past 12 months; the latest release was about 15 months ago, which raises abandonment concerns.

Repo popularitycaution

The repository has one star and no forks, providing little evidence of external adoption or review. Low popularity is supporting evidence rather than proof of poor quality.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

何强春

Direct Dependencies

DependencyLast ReleaseScore
nyholm/psr7
Version ^1.5
—
—
symfony/mime
Version ^5.4|^6.0
—
—
symfony/cache
Version ^6.0
—
—
psr/simple-cache
Version ^3.0
—
—
nyholm/psr7-server
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform