Package Health

lockally/sdk

The package has substantial documentation, tests, organizational ownership, and read-only workflow permissions. Its licensing metadata conflicts with the detected MIT license, and the workflows use unpinned actions, so pinning this early release deserves care.

Latest 0.1.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The artifact and repository contain a license file, but the manifest declares Unlicense while the detected file is MIT. The package is licensed, yet the mismatch reduces clarity for adopters.

Release historycaution

This is a 48-day-old package with only one published release. That limits evidence of release stability and long-term maintenance.

Repo bus factorcaution

One contributor made 100% of the two recent commits. Organizational ownership provides some handoff capacity, but no second active contributor is shown.

Repo commit activitycaution

Only two commits were recorded in the last three months. Recent activity exists, but the small volume provides limited evidence of sustained maintenance.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. For a young SDK, the missing scanning is a modest transparency and maintenance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

OpenAPI

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^1.7 || ^2.0
guzzlehttp/guzzle
Version ^7.3

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform