Package Health

mencoro/mencoro-api-sdk

Its workflows use read-only job permissions, and the package includes a substantial README and matching source tree. The organization-backed project has no security policy and uses unpinned action references, so operational hygiene is only moderate.

Latest v1.0.1PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package was first released today and has only two releases, so there is not yet enough history to demonstrate sustained maintenance. Its stable v1.0.1 version provides some maturity signal but does not offset the lack of track record.

Repo commit activitycaution

The repository records zero commits and zero active maintainers over the last three months. Because the project is brand new, this is limited evidence rather than proof of abandonment, but maintenance capacity is not yet demonstrated.

Security policycaution

The linked repository has no security policy, leaving vulnerability-reporting expectations unclear for an API client. The repository is organization-backed, but that does not replace a published security process.

Workflow auditcaution

All 29 analyzed action references are unpinned, which weakens build reproducibility. Both workflows use read-only permissions, and the cache-poisoning finding has low confidence, so this is a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mencoro Support

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^1.7 || ^2.0
—
—
guzzlehttp/guzzle
Version ^7.3
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform