Package Health

smmtglux/smm-api

This is a small, cleanly packaged PHP client with an MIT license, README, tests, a complete eight-file source/artifact tree, no install-time scripts, minimal runtime requirements, and organization-backed repository ownership. It is not deprecated or archived, and the repository README explicitly references the package despite the repository name mismatch. However, the release is brand new with only one release, zero recorded commits or active maintainers in the measured three-month window, no security policy or security scanning, and no demonstrated adoption, so maintenance maturity and long-term continuity remain unproven. It is usable as a dependency, but should be adopted with version pinning and monitoring for follow-up releases and repository activity.

Latest v1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historycaution

Only one release exists and the package is less than one day old, so there is no demonstrated release cadence or maintenance history yet.

Repo commit activitycaution

The measured three-month window contains zero commits and zero active maintainers, leaving maintenance capacity unproven; the repository's very recent push partly explains this result but does not establish continuity.

Repo popularitycaution

The repository has zero stars, forks, and watchers, indicating no demonstrated external adoption; because the package is newly released, this is a maturity caution rather than a severe risk.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured, leaving a modest repository hygiene gap for a package intended as a dependency.

Security policycaution

No security policy is present, which reduces vulnerability-reporting transparency, though the small package has no other provided security-policy evidence to offset the gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

TGLUX

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
20 days ago
Created
20 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform