Package Health

fond-of-oryx/concrete-product-api

The source includes tests, a matching repository, and a clear MIT license. Its small audience and missing security policy add modest transparency concerns, while recent development appears limited.

Latest 3.0.0PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

Only three releases are recorded, with the latest on February 1, 2023 and no releases in the last 12 months. That long publishing gap raises maintenance and abandonment concerns.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. Although the repository was pushed in January 2025, the current inactivity still weakens confidence in ongoing maintenance.

Repo toolingcaution

The project uses Make and Composer, showing basic build structure, but no security-scanning tooling was detected. This is a modest hygiene gap rather than a severe dependency risk.

Security policycaution

No security policy was found in the linked repository. That reduces transparency about vulnerability reporting and response, especially for a package integrated into applications.

Workflow auditcaution

The workflow audit completed successfully and found no dangerous triggers, untrusted checkouts, or audit findings. However, all three referenced actions are unpinned, leaving the build exposed to reference changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Rose
Pascal Fischer

Direct Dependencies

DependencyLast ReleaseScore
spryker/api
Version ^0.4.0
—
—
spryker/product
Version ^5.0.0 || ^6.0.0
—
—
spryker/api-extension
Version ^0.1.0
—
—
spryker/api-query-builder
Version ^0.1.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform