The artifact is licensed, well documented, and backed by repository tests, with no install-time scripts. Its only release is too new to establish maintenance, and the project has no security scanning or security policy.
64%
Total Score
50
100
79
83
The package was first and last released 0 days ago and has only one release, so there is no release record to demonstrate sustained maintenance. Its repository was pushed immediately before assessment, which makes this a maturity concern rather than evidence of abandonment.
There were no commits or active maintainers in the previous 3 months, but the repository and package are only 0 days old. This leaves maintenance capacity unproven rather than showing a collapsed project.
Composer build tooling is present, but no security scanning tools were detected. For a package containing native iOS and Android code, the missing automated security checks are a modest transparency gap.
The repository has no security policy. This does not show a vulnerability, but it gives users no documented route for reporting security issues in a package that ships native code.
Version 0.0.1 is an early development release, so compatibility and API stability are not yet established. It is not marked as a prerelease, but the version itself still indicates limited release maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nativephp/mobile Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.