Package Health

fond-of-oryx/credit-memo

The repository includes tests and the package has a clear MIT license. Its workflow uses three unpinned actions and has no security scanning, adding maintenance and build-integrity concerns.

Latest 2.0.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has eight releases since June 2021, but its latest release was about 18 months ago and there were no releases in the last 12 months. This indicates materially slowed maintenance.

Repo commit activitycaution

The repository had no commits and no active maintainers during the last three months. The non-archived repository and existing release history provide some context, but current maintenance is not evident.

Repo toolingcaution

The project uses Make and Composer, but no security scanning tools were detected. That is a transparency and maintenance gap for a package with substantial runtime dependencies.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers or audit findings, but all three referenced actions are unpinned. This leaves build inputs less reproducible than they could be.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Rose
Jozsef Geng
Julian Hyatt

Direct Dependencies

DependencyLast ReleaseScore
spryker/log
Version ^1.0.0 || ^2.0.0 || ^3.0.0
—
—
spryker/oms
Version ^6.0.0 || ^7.0.0 || ^8.0.0 || ^10.0.0 || ^11.0.0
—
—
spryker/sales
Version ^8.0.0 || ^10.0.0 || ^11.0.0
—
—
spryker/store
Version ^1.1.0
—
—
spryker/payment
Version ^3.0.0 || ^4.0.0 || ^5.0.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform