Package Health

indeximstudio/shipengine

The package is licensed, documented, tested, and backed by an active organization-owned repository. Workflow hygiene needs attention: insecure commands were detected and all four action references are unpinned, while recent repository activity is absent.

Latest v3.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months, which is a meaningful sign of currently limited maintenance activity.

Repo popularitycaution

The repository has zero stars, forks, and watchers, providing no community adoption signal to offset the thin recent activity evidence.

Repo toolingcaution

The project uses Make and Composer, but no security scanning tools were detected; this is a modest repository hygiene gap rather than evidence of abandonment.

Security policycaution

No security policy was found in the repository, leaving vulnerability-reporting expectations unclear for an API client library.

Workflow auditcaution

Both workflows were analyzed successfully with no untrusted checkout or injection sinks, but all four action references are unpinned and a high-confidence insecure-commands finding was reported in CI. These are workflow hygiene risks, not standalone evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

shipengine/shipengine contributors

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0.1
—
—
php-http/httplug
Version ^2.2.0
—
—
php-http/message
Version ^1.10.0
—
—
psr/http-factory
Version ^1.1.0
—
—
psr/http-message
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform