Package Health

fond-of-oryx/customer-product-list-connector

Tests, an organization-owned matching repository, and a clear MIT license support adoption. All three workflow actions are unpinned, no security policy is present, and recent commit activity is absent.

Latest 2.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has had no release in about 3 years and 8 months, with zero releases in the last 12 months. This is a meaningful maintenance concern despite four total releases and a regular earlier cadence.

Repo commit activitycaution

There were no commits and no active maintainers in the last 3 months. This raises a maintenance concern, although the repository's January 2025 push and organization backing provide some compensating evidence.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a hygiene gap, not evidence that the package is unsafe by itself.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 3 action references are unpinned, creating a modest reproducibility and workflow-supply-chain weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Rose

Direct Dependencies

DependencyLast ReleaseScore
spryker/log
Version ^3.9.0
—
—
spryker/product-list
Version ^1.0.0
—
—
fond-of-spryker/product-list-customer
Version dev-spryker_upgrade
—
—
fond-of-oryx/customer-product-list-connector-extension
Version ^1.0.0 || ^2.0.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform