Package Health

qopanza/sdk

This is a very new, early-stage release with only one published version, so its long-term maintenance and stability are not yet demonstrated. The package is nevertheless licensed, small in scope, has a README and tests in both the artifact and repository, declares a minimal dependency profile, has no install-time scripts, is not deprecated or archived, and its repository explicitly explains the mirror and package relationship. The absence of security tooling and a security policy leaves transparency and assurance gaps, but the available evidence does not indicate that the package is currently unfit to adopt; depend on it cautiously and reassess after a history of releases and maintenance develops.

Latest v0.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historycaution

The package is only 1 day old and has a single release, so there is not yet enough release history to establish maintenance continuity or maturity.

Repo commit activitycaution

There were no commits and no active maintainers in the last 3 months, but this is consistent with the package being only 1 day old; it still leaves ongoing maintenance unproven.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured, leaving a genuine repository assurance gap.

Security policycaution

The repository has no security policy, reducing transparency around vulnerability reporting and response expectations.

Version stabilitycaution

The current version is v0.1.0 rather than a stable major release, which indicates an early API and maturity stage even though it is not marked as a prerelease.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Gsente LLC

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
18 days ago
Created
18 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform