Package Health

bitbag/vue-storefront2-plugin

Sylius backend integration for Vue Storefront 2

Latest v1.5.0PackagistPackagist

42%

Total Score

unhealthy

Risky: releases stopped about three years ago and repository commits have been inactive for more than two years.

Health Score Breakdown

Release historydanger

The package has had no release in about three years, despite a previously regular median interval of about 24 days. That long gap is a substantial abandonment concern.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the prolonged release gap and indicating no current maintenance activity.

Repo issue activitycaution

No issues or pull requests were opened, closed, or merged in the last month, while five issues and four pull requests remain open. This supports the picture of an inactive project.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, although it is less serious than the maintenance inactivity.

Workflow auditcaution

All 8 analyzed action references are unpinned, which weakens build reproducibility. The reported cache-poisoning findings are low-confidence hygiene observations, so they do not independently raise this to severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
sylius/sylius
Version ~1.11.0
—
—
symfony/mailer
Version ^6.0
—
—
webonyx/graphql-php
Version ^14.9
—
—
bitbag/wishlist-plugin
Version ^3.0
—
—
php-http/message-factory
Version ^1.1
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform