Package Health

crowdhandler/sdk

This is a usable, actively published stable package with a BSD-3-Clause license, a non-archived organization-backed repository, recent release activity, and no install-time lifecycle scripts. However, maintenance depth and transparency are limited: only one contributor made one commit in the last three months, the repository has no tests, changelog, security policy, or security scanning, and the repository has negligible public adoption. The recent release and two merged pull requests provide meaningful evidence of ongoing activity, but the thin recent contributor base warrants caution before adopting it for a critical dependency.

Latest 1.0.10PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Package scaffoldingcaution

A substantial README documents API usage, but neither the artifact nor repository contains tests or a changelog. The documentation is useful, yet the absence of both testing and release-history documentation reduces maintenance transparency.

Repo bus factorcaution

All three-month commit activity is concentrated in one contributor with a 100% share. Organization ownership provides some potential handoff capacity, but no second recently active contributor is evidenced.

Repo commit activitycaution

Only one commit was made in the last three months by one active maintainer. Recent release activity offsets this somewhat, but the low commit volume is a genuine maintenance-capacity concern.

Repo popularitycaution

The repository has 0 stars, 1 fork, and 0 watchers, indicating very limited visible adoption. Popularity is supporting evidence rather than decisive, but this provides little external validation.

Repo toolingcaution

Composer is used as a build tool, which is appropriate for a PHP package, but no security scanning tooling is present. The missing scanning is a transparency gap rather than a standalone health failure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

richard-mutt-crowdhandler
lthornton-mm
luke-owen-crowdhandler

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
10 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform