Package Health

exewen/digital-signature-php-sdk

The README is substantial, tests cover the repository, and Apache-2.0 licensing is clear. The package has a small but coherent source tree and no install-time scripts, limiting avoidable adoption risk.

Latest v2.0.0PackagistPackagist

56%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

80

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package is 858 days old with six releases, but it has had no releases in the last 12 months; the latest release was about 18 months ago. This is a meaningful maintenance concern for an SDK tied to evolving API standards.

Repo commit activitycaution

The repository shows zero commits and zero active maintainers in the last three months, while its last push was about 18 months ago. That suggests maintenance has paused, although the package may be intentionally stable.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools are configured. For a package handling signing and validation, this leaves a notable maintenance and review gap.

Security policycaution

The repository has no security policy. This reduces transparency about how vulnerability reports are handled, though it is not evidence of a vulnerability by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

exewen

Direct Dependencies

DependencyLast ReleaseScore
runz0rd/mapper-php
Version ^2.2
—
—
phpseclib/phpseclib
Version ~3.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform