Package Health

nogrod/dhl-retoure-php-sdk

This release is usable and reasonably transparent: it has a five-year history, 11 releases with five in the last 12 months, a non-prerelease version, a matching repository, documented usage, source tests, and a license file. However, maintenance capacity is uncertain because the repository has had no commits or active maintainers in the last three months, the project has negligible adoption signals, and it lacks both security scanning and a security policy. The generated-SDK structure and recent release activity partly offset the absence of recent repository commits, but this remains a package to adopt with some maintenance and security-process caution.

Latest v0.2.7PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Project backingcaution

The repository is owned by a user account rather than an organization, so there is no demonstrated institutional backing. This makes the zero recent commit activity more consequential than it would be for a clearly organization-owned project.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance concern. Recent registry releases provide partial compensating evidence, especially for a generated SDK, but do not demonstrate ongoing source development.

Repo issue activitycaution

There are no open issues or pull requests and no activity in the last month. This avoids an unresolved-work backlog, but it also provides no evidence of an active user or contributor community.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher, indicating very limited external adoption. Popularity is supporting evidence rather than a decisive health verdict, but this reduces confidence in community resilience.

Repo toolingcaution

Composer is used as a build tool, which supports reproducible package structure, but no security scanning tools are configured. The missing scanning process is a security-hygiene gap rather than evidence of maliciousness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

OpenAPI-Generator contributors

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^2.0
guzzlehttp/guzzle
Version ^7.4.5

Weekly Downloads

Info

Last Published
21 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform