Package Health

lcbrq/magento-lcb_attachments

The stable MIT package has a README, no install scripts, and a matching non-archived repository. Its tiny audience and absent security tooling leave less evidence of mature ongoing support, while release and commit activity are sparse.

Latest 1.4.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

Only two releases have appeared over about 22 months, with a median interval of about 18 months and one release in the last year. This indicates slow maintenance, though a recent release provides some evidence the package is not abandoned.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last three months. The recent release push is some compensating evidence, but the current absence of development activity still raises maintenance risk.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 3 watchers. Popularity is supporting evidence rather than a verdict, but these numbers provide little independent evidence of broad review or community support.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are configured. The missing scanning is a transparency and hygiene gap, not evidence that the package is unsafe.

Security policycaution

The repository has no security policy. For a plugin handling attachment downloads and uploads, this leaves vulnerability reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Silpion Tomasz Gregorczyk

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform