Testing, documentation, and an MIT license make the release transparent to integrate. The repository is not archived and clearly matches the package, but maintenance capacity remains unproven.
64%
Total Score
50
100
88
75
The package is only 1 day old, with five releases clustered about 2 minutes apart. This shows active initial publishing but provides almost no evidence of sustained maintenance or release stability.
There were no commits or active maintainers recorded in the last 3 months. Because the package is only 1 day old, this is partly explained by its youth, but ongoing maintenance is still unproven.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest repository-hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.
The single workflow was fully analyzed with no reported audit findings or untrusted checkouts, but all four action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nativephp/mobile Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.