Package Health

devcbh/sms-wrapper

The package includes a consumer-facing README, tests, a complete small file tree, and release notes for this version. Its proprietary licensing, single-person maintenance, burst-only release history, and lack of security tooling leave meaningful long-term dependency concerns.

Latest 1.0.3PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Licensecaution

The package declares a proprietary license and includes both a LICENSE file and repository license file. It is licensed, but the proprietary terms may restrict use compared with a conventional open-source license.

Maintainerscaution

Only one registry maintainer is listed. The linked repository is owned by the same individual, so this is consistent with a small personal project but leaves limited redundancy.

Release historycaution

All four releases arrived within one day, with no later release activity observed over the package's 220-day age; this suggests limited evidence of sustained maintenance.

Repo toolingcaution

Composer is used for builds, but no repository security-scanning tools were detected, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy. This is a minor transparency gap for a package that handles an external SMS service, though it is not evidence of unsafe behavior by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christian Villegas

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.0
illuminate/support
Version ^9.0|^10.0|^11.0|^12.0

Weekly Downloads

Info

Last Published
7 months ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform