Package Health

tribepeer/sdk

This is a coherent, licensed PHP SDK with a small and understandable artifact, no install-time lifecycle scripts, a non-archived repository, and no registry deprecation. However, v0.1.0 was released only minutes before assessment and is the sole release, so maintenance and stability are unproven; the repository has no observed commit activity beyond initial publication, no tests or changelog, no security scanning, and no security policy. The README does identify the package and its repository, which supports provenance, but the single-user ownership and absence of broader adoption make this better treated as an early-stage dependency requiring validation and monitoring rather than a mature, low-risk foundation.

Latest v0.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry publishing account is listed, limiting visible publishing redundancy. The repository is user-owned, so there is no organization backing shown to compensate for the thin maintainer base.

Package scaffoldingcaution

A README and GitHub Releases support basic usability and release communication, but neither the artifact nor repository contains tests or a changelog. For a new SDK, the lack of tests is a meaningful maintenance and reliability gap.

Project backingcaution

The repository owner is a single user account rather than an organization, providing limited visible institutional backing. This matters more because the release has no established maintenance history.

Release historycaution

There is only one release and the package age is 0 days, so there is no historical evidence of sustained maintenance or release reliability. This is a substantial maturity concern, although it does not establish abandonment for a newly published package.

Repo commit activitycaution

The repository records zero commits and zero active maintainers in the preceding three months, consistent with a repository created very recently. This leaves ongoing maintenance capacity unverified rather than proving that development has ceased.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

devadu integrated solutions

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.2
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
17 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform