Package Health

jpmmartin/sylius-shipping-carriers-plugin

Documentation, tests, and two active contributors provide a solid starting point. All workflow actions are unpinned and the repository lacks a security policy, so prefer a later established release when available.

Latest v1.1.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Project backingcaution

The repository is owned by the individual user jpmmartin rather than an organization, so the small two-person contributor base represents the project's actual visible maintenance capacity.

Release historycaution

The package is only 1 day old with two releases, so its maintenance pattern and compatibility over time are not yet demonstrated. The 158 recent repository commits provide useful activity but cannot replace a longer release history.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. Composer auditing partly compensates for this operational gap but does not replace a policy.

Workflow auditcaution

Both workflows were analyzed successfully with no untrusted checkouts or script injection, and the cache-poisoning findings are low-confidence hygiene warnings. However, all 13 action references are unpinned, which weakens build reproducibility and supply-chain integrity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/lock
Version ^6.4 || ^7.4
—
—
sylius/sylius
Version ^2.2.6
—
—
paragonie/halite
Version ^5.0
—
—
league/flysystem-bundle
Version ^3.3
—
—
shipstream/fedex-rest-sdk
Version ^1.6
—
—

Weekly Downloads

Info

Last Published
21 hours ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform