suning sdk for composer package
38%
Total Score
unhealthy
Risky: no release or commit activity since 2018 leaves the package effectively unmaintained.
A license file is present and the repository also has one, so licensing is not absent; however, the artifact declares MIT while the detected license text is Apache-2.0, creating a material licensing ambiguity.
The package has only one release, published about eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency that may need compatibility updates.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release hiatus. No provided signal shows compensating recent maintenance.
The repository has no security policy and no security-scanning tools. For an unmaintained package, this provides little evidence that vulnerabilities would be reported or addressed promptly.
The only available version is 0.0.1 and it is not a stable major release. With no later releases to demonstrate maturation, this leaves compatibility and maintenance risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.