Package Health

dilneiss/mercadolibre-php-sdk

It includes tests, release notes, and a clear license. The repository is not archived and the package has a manageable dependency set, but future fixes and support are uncertain.

Latest v3.0.3PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, and the project backing identifies a user-owned repository rather than an organization. This thin publishing base adds some continuity risk alongside the inactive repository.

Package scaffoldingcaution

The package includes a README, tests, and a GitHub release with notes for this version. The README also states that the project is no longer maintained, which materially offsets the otherwise useful documentation.

Release historycaution

Only three releases exist since August 2021, with no release in the past 12 months and a median interval of about 650 days. This indicates a very slow maintenance cycle for an SDK.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the past three months. Together with the maintenance warning in the README, this raises a substantial abandonment concern.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible community activity provides no compensating adoption signal.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mercado Libre

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.4.1

Weekly Downloads

Info

Last Published
1 year ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform