Package Health

altapay/magento2-community

This is a healthy, actively maintained release with a long release history, frequent recent releases, stable versioning, an active non-archived organization-backed repository, documented tests and changelog, a clear MIT license, and a small runtime dependency surface. The main concerns are that all recent repository commits came from one contributor, repository popularity is low, no security policy is present, and workflow permissions and one script-injection finding warrant review; these reduce resilience and transparency but do not outweigh the strong release and project activity evidence.

Latest 4.2.5PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

Four workflows were analyzed with no pull_request_target or untrusted checkout findings, but one deployment workflow contains a script-injection pattern; deployment workflow inputs should be reviewed before relying on the repository.

Repo bus factorcaution

One contributor made 100% of the 9 commits in the last 3 months, creating a low short-term bus factor. Organization ownership provides some handoff capacity, so this is caution rather than a severe abandonment finding.

Repo commit activitycaution

There were 9 commits in the last 3 months, demonstrating recent work, but all were produced by one active maintainer; the activity is healthy while the concentration remains a resilience concern.

Repo popularitycaution

The repository has only 2 stars, 6 forks, and 7 watchers, which indicates limited external adoption evidence; popularity is supporting evidence rather than a health verdict, and the active release and repository signals compensate for this gap.

Security policycaution

No SECURITY.md or equivalent security policy was found, reducing vulnerability-reporting transparency. This is a hygiene concern rather than evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
altapay/api-php
Version ^3.5.9
—
—

Weekly Downloads

Info

Last Published
22 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform