Package Health

2performant/business-league-marketing

This is a usable, transparently packaged Magento 2 extension with a declared GPL-3.0-or-later license, stable releases, strong unit and integration test coverage, an unarchived organization-owned repository, and a recent release cadence. The main concern is maintenance continuity: the repository shows zero commits and zero active maintainers in the last 3 months despite a recent package release, while the project has no security scanning or security policy and has very limited public adoption. The package is therefore reasonable to evaluate and use with monitoring, but it does not provide the evidence of sustained maintenance expected for a highly healthy dependency.

Latest 1.1.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Lifecycle scriptscaution

The package uses post-install-cmd and post-update-cmd scripts, which add installation-time behavior and deserve review before adoption, but this is not by itself evidence of poor maintenance or unfitness.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, which is a meaningful concern about maintenance continuity despite the recent registry release.

Repo popularitycaution

The repository has 0 stars, 1 fork, and 0 watchers, indicating very limited public adoption. Popularity is supporting evidence rather than a decisive health criterion, so this is a caution rather than a severe risk.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage is a genuine supply-chain hygiene gap, though it is not a health verdict by itself.

Security policycaution

The repository has no security policy, reducing transparency around vulnerability reporting and response expectations for a package that processes checkout and tracking behavior.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
11 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform