Package Health

buckaroo/magento2

This release appears healthy and suitable for dependency consideration: it has a long release history with 110 releases since 2020 and 24 releases in the last 12 months, is stable and not deprecated, and is backed by an active non-archived organization repository. Recent activity is strong, with 155 commits and 36 merged pull requests in the last three months from four active contributors. The package includes a README, tests, a license, and no install-time lifecycle scripts. Remaining concerns are limited to repository security hygiene: no automated security scanning was detected and none of the four workflows declares top-level token permissions, while the repository's 65% top-contributor share warrants monitoring despite organization backing and multiple active contributors.

Latest v2.7.1PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected; this is a modest repository hygiene gap rather than a standalone adoption blocker.

Token permissionscaution

All 4 workflows lack top-level permissions declarations. No workflow requests top-level write access, but explicitly declaring least-privilege permissions would improve CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Buckaroo

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0 || ^3.0
buckaroo/sdk
Version ^1.24.3
monolog/monolog
Version ^2.9 || ^3.0
magento/framework
Version >=103.0.0
magento/module-ui
Version ^101.2

Weekly Downloads

Info

Last Published
12 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform