Package Health

zskenny/wechat-php-sdk

The package is small and easy to audit, with an MIT license and no install-time scripts. Its release and repository activity stopped in 2021, with no tests or security policy to show ongoing maintenance. Pinning this version would leave you dependent on an apparently abandoned SDK.

Latest 1.0.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has had only two releases, with none in the last 12 months, and its latest release was in April 2021. This is strong evidence of abandonment for a library that may need compatibility and security updates.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. No newer activity compensates for the stale release history.

Package scaffoldingcaution

The artifact includes a README and the version has a GitHub release; the absence of tests and a changelog is normal for published artifacts and is not itself a gap. However, the README is only 20 characters, offering little consumer guidance.

Repo toolingcaution

Composer is used for the build, which is appropriate, but no security-scanning tooling is present. This is a modest transparency and maintenance gap rather than evidence of a direct security problem.

Repository archivedcaution

The repository is not archived, which avoids the strongest abandonment signal, but its last push was in May 2021 and does not offset the lack of recent commits.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

zskenny

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform