Usable with caveats: the package is clearly licensed, documented, tested, and not deprecated, but it is brand new with only two releases and no observed commit activity yet. Its single-maintainer project also has no security policy or scanning, so long-term maintenance is unproven.
62%
Total Score
50
100
88
75
Only one account has registry publish access. This is a real continuity risk for a user-owned project because there is no demonstrated maintainer redundancy.
The registry namespace and repository owner match, but the repository is owned by an individual rather than an organization. That is consistent ownership, though it offers less backing than an established project organization.
This package is extremely new: it was first released today and has only two releases, so there is not enough history to establish durable maintenance or release practices.
The repository records zero commits and zero active maintainers in the last three months. Because the project is brand new, this is more a lack of maintenance evidence than proof of abandonment, but it leaves long-term support unproven.
Composer is used as the build tool, but no security scanning tools are configured. That is a transparency and maintenance gap for a package intended to be installed as a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nativephp/mobile Version ^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.