Yinxiang PHP SDK
35%
Total Score
unhealthy
Risky: no activity since 2015, an unverified repository link, and conflicting license signals.
The package has had no releases in more than 11 years: all four releases were published in February 2015, with none in the last 12 months. This strongly indicates abandonment despite the stable 2.0.0 version.
The linked repository has recorded zero commits and zero active maintainers in the last three months, consistent with its last push in February 2015. No newer activity compensates for this prolonged maintenance gap.
The artifact declares Apache while its license file is recognized as BSD-2-Clause; although license files are present, the mismatch requires clarification before adoption.
The registry namespace is Evernote, but the linked repository is owned by an individual user rather than an organization. This provides no clear organizational backing for continued maintenance.
The repository name does not match the package name and its README does not mention the package, so the link may not represent the package's actual upstream project. That weakens provenance and maintenance confidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.