Package Health

frosh/shopmon-cli

The project has two active contributors, recent releases, release notes, and a clear README. MIT licensing, organization backing, and no install-time scripts reduce adoption friction, while security documentation is limited.

Latest 0.0.10PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

Two contributors split recent commits evenly, so maintenance is not concentrated in one person; the small contributor pool still limits redundancy.

Repo toolingcaution

The project uses Composer build tooling, but no security scanning tools were observed, leaving a modest assurance gap.

Security policycaution

No repository security policy is present, reducing transparency about vulnerability reporting and maintenance response.

Version stabilitycaution

Version 0.0.10 is not a stable major release, so the API may still change; it is nevertheless a normal non-prerelease release.

Workflow auditcaution

All seven action references are unpinned, and release automation has a high-confidence template-injection finding plus top-level write permissions; no untrusted checkout or script-injection trigger was found, so this is a serious hygiene concern rather than a standalone critical verdict.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 month ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform