Package Health

thinksvip/lazada-sdk

It has a clear Apache-2.0 license, a matching repository, and no install-time scripts. The small codebase has no tests or security policy, and its single maintainer has not committed in over four years, leaving this beta release with limited maintenance assurance.

Latest v0.0.1-beta5PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has only 5 releases and none in the last 12 months; its latest release was in March 2022, over four years ago, which is a strong abandonment concern.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no activity since March 2022.

Package scaffoldingcaution

The package includes a README and uses GitHub releases, but it has no tests or changelog; the missing tests reduce confidence in a small library that consumers integrate directly.

Security policycaution

The linked repository has no security policy, leaving no documented process for reporting and handling security issues.

Version stabilitycaution

The assessed version is still a prerelease beta, and all recent releases were prereleases, so the public API and behavior may not be stable.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

thinksvip

Direct Dependencies

DependencyLast ReleaseScore
netresearch/jsonmapper
Version *

Weekly Downloads

Info

Last Published
4 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform