Package Health

craftcms/shopify

This is a healthy, mature release with nearly eight years of history, 60 releases, 17 releases in the last 12 months, and a recent stable release. The linked organization-owned repository is active, unarchived, package-matched, tested, documented, and backed by substantial recent commit and pull-request activity. The main reservations are that one contributor made 81.25% of recent commits, repository security scanning was not detected, and two workflows lack top-level permission declarations; these are meaningful hygiene considerations but are moderated by active secondary contributors, organization backing, a security policy, and the absence of detected dangerous workflow patterns.

Latest 8.1.0PackagistPackagist

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

The top contributor made 81.25% of recent commits, creating concentration risk. The two additional contributors remain active, and organization ownership provides some ability to hand maintenance off, so this is a caution rather than a severe risk.

Repo toolingcaution

Composer build tooling is present, but no repository security-scanning tool was detected. The missing scanning automation is a hygiene gap, though other security signals provide partial compensation.

Token permissionscaution

Two workflows lack top-level permission declarations, which weakens least-privilege clarity. However, no workflow has top-level write permissions, and the analyzed workflows include read-only or job-level permission controls, limiting the concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^5.10.7
—
—
guzzlehttp/guzzle
Version ^7.2
—
—
carnage/php-graphql-client
Version ^1.14
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform