Package Health

joshua-barbosa/erede-sdk

Usable with caveats: it has a clear MIT license, substantial documentation, tests, and a matching source repository, but this is a very young v0 package with only three releases over roughly 12 hours and no demonstrated activity after its initial publication. A single maintainer and limited repository security hygiene add dependency risk.

Latest v0.2.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

Seven runtime dependencies are declared, including Laravel components, Guzzle, PSR logging, and Symfony HTTP Foundation. This is a meaningful integration surface for a small pre-1.0 SDK but is broadly consistent with its stated Laravel role.

Maintainerscaution

Only one registry account has publish access. The matching user-owned repository provides some accountability, but the single-person maintainer base leaves limited redundancy if the maintainer becomes unavailable.

Project backingcaution

The package and repository are both owned by the same individual account, so the source identity is consistent. It is not organization-backed, which offers less institutional continuity than an organization-owned project.

Release historycaution

The package is only about 50 days old and has three releases, all clustered within roughly 12 hours; this provides little evidence of sustained maintenance or long-term release discipline.

Repo issue activitycaution

There are no open issues or pull requests and no activity in the last month. With a repository only about 50 days old, this does not prove abandonment, but it provides no evidence of an active feedback or maintenance cycle.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joshua Barbosa

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1|^2.0|^3.0
illuminate/http
Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0
guzzlehttp/guzzle
Version ^7.5
illuminate/support
Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0
illuminate/contracts
Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform