HeyCart 6 conflicting packages
40%
Total Score
unhealthy
Risky: no release in over a year, with only four releases and an extremely thin package artifact.
Only four releases have been published, and none appeared in the last 12 months; the latest release was about 14 months before collection. That is strong evidence of stalled maintenance for a package only about 15 months old.
The artifact contains only .gitignore and composer.json, leaving little implementation or usage material visible for consumers. This thin package layout reduces transparency and makes the release difficult to evaluate.
No README, tests, or changelog are present in the published artifact. Missing tests and changelog are normal for a package artifact, but the missing README is a genuine consumer-guidance gap for a library.
Version 0.6.0 is not a prerelease, so it is presented as a usable release, although the pre-1.0 major level signals a still-evolving API. The release history provides the more significant maintenance concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
heycart/core Version >=6.7.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.