Package Health

fastly/magento2

This is a mature, actively released package with 267 releases over more than 10 years, 15 releases in the last 12 months, a stable non-prerelease version, a non-deprecated registry status, and a current unarchived repository owned by the Fastly organization. The artifact is substantial and well documented, with tests, a changelog, Composer build tooling, and a clear BSD-3-Clause license. Recent repository activity is present across three maintainers, although commit volume is modest and several repository security-hygiene gaps remain: no security policy or security-scanning tools, undeclared top-level workflow token permissions, and one workflow flagged for script injection. These warrant review of the CI configuration but do not outweigh the strong maintenance and project-backing evidence.

Latest 1.2.248PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Are you affected? Scan for Free

Health Score Breakdown

Dangerous workflowscaution

One of four analyzed workflows, delete-bot-branch.yaml, was flagged for script injection. This is a concrete CI hygiene concern, although no pull_request_target, workflow_run, or untrusted-checkout risks were detected.

Repo toolingcaution

Composer build tooling is present, supporting reproducible project workflows, but no security-scanning tools were detected, leaving a security-hygiene gap.

Security policycaution

The repository has no SECURITY.md or other detected security policy, reducing transparency around vulnerability reporting and response procedures.

Token permissionscaution

All four workflows lack top-level token-permission declarations. No workflow declares top-level write access, but explicitly constraining permissions would provide stronger CI hardening.

Vulnerabilities

TitleVersionsSeverity
CVE-2017-13761
fastly/magento2 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 1.2.26.
0.0.0 - 1.2.26
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
magento/framework
Version >=103.0.0
—
—
zordius/lightncandy
Version ^1.2
—
—
laminas/laminas-http
Version ^2.6.0
—
—
magento/module-store
Version >=101.1.0
—
—
magento/module-config
Version >=101.2.0
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform