Package Health

divante-ltd/coreshop-vsbridge

Usable with caveats, but maintenance appears stalled: the latest release was in February 2021 and the repository has had no recent commits or issue activity. It has clear ownership, tests, documentation, release notes, and licensing, but should be adopted only if its older Pimcore and CoreShop dependencies remain suitable.

Latest 0.3.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months. Combined with the old latest release, this is the main abandonment concern for depending on the package.

Dependency profilecaution

Ten runtime dependencies, including Pimcore, CoreShop, Symfony, Elasticsearch, and JWT bundles, create a broad compatibility surface. The dependencies fit the documented bridge package, but their age increases the cost of using an apparently inactive release.

Release historycaution

The package has eight releases and a regular historical cadence, but its latest release was on February 26, 2021, with no releases in the last 12 months. This long release gap is a meaningful maintenance concern.

Repo issue activitycaution

The repository has 12 open issues and four open pull requests, but recorded new or closed issues and pull requests are all zero for the last month. Unresolved work without current activity suggests limited maintenance capacity.

Repo toolingcaution

Composer is used for the build, but no security scanning tools are present. The missing scanning is a transparency gap, though it is less decisive than the maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
cocur/slugify
Version ^3.1
pimcore/pimcore
Version ^5.8 | ^6.0
coreshop/core-shop
Version ^2.1
nelmio/cors-bundle
Version ^1.5
gfreeau/get-jwt-bundle
Version ^2.0

Weekly Downloads

Info

Last Published
5 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform