Package Health

xcily/aliyun-dysms-php-sdk

Risky to adopt: this package has had only one release, published about 8 years ago, with no recent commits or active maintainers. Its license, tests, minimal dependencies, and clean package structure provide some reassurance, but the lack of ongoing maintenance is a serious concern.

Latest v1.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historydanger

The package has only one release, and its latest release was published about 8 years ago; there have been no releases in the last 12 months. This is strong evidence of an abandoned or frozen dependency.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long gap since its only release. No provided signal shows compensating recent maintenance.

Package scaffoldingcaution

The published artifact has no README, which makes integration harder for a PHP SDK, although the source repository does contain tests. The missing changelog is normal packaging practice and is not treated as a gap here.

Repo popularitycaution

The repository has 0 stars, 0 forks, and 1 watcher, so there is little visible community adoption to compensate for the lack of maintenance.

Repo toolingcaution

The repository uses Composer, but no security scanning tools are configured. This is a modest transparency gap, though the absence of workflows also limits workflow-specific risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aliyuncs

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
8 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform