Package Health

nexorams/sdk

This release has solid initial engineering and transparency indicators: it is MIT-licensed, includes a substantial README, changelog, tests, a complete source tree, Composer-based build tooling, security scanning, and a workflow without the analyzed dangerous patterns. The main limitation is maturity: the package is less than a day old with only two releases, zero observed commits or active maintainers in the three-month window, and no repository security policy. Those activity metrics are not yet strong abandonment evidence because the project is newly published, but they leave maintenance continuity unproven. The organization-backed repository and explicit package reference are reassuring, so the package is usable but should be adopted with monitoring rather than treated as mature.

Latest v1.0.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historycaution

The package is extremely new, with only two releases since its first publication less than a day ago; this limits evidence of sustained maintenance and release discipline.

Repo commit activitycaution

No commits or active maintainers were observed in the three-month window. This is a meaningful maintenance-visibility gap, although the package's age means the window largely predates publication.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Given that it was created very recently, this is weak maturity evidence rather than a standalone health failure.

Security policycaution

No security policy is present in the repository, leaving vulnerability-reporting and security-response expectations undocumented.

Token permissionscaution

The sole workflow lacks top-level GitHub token permissions. Although no write permissions are explicitly requested, least-privilege intent is not clearly declared.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nexora Platform Team

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.8
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
17 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform