Package Health

mage-os/module-automatic-translation

This release appears healthy and suitable to depend on: it has a stable release line, frequent recent publishing, an active non-archived organization-backed repository, five active contributors in the last three months, tests, a changelog, a license file, and no install-time lifecycle scripts. The main reservations are the absence of a security policy and security scanning, plus a GitHub Actions workflow using pull_request_target and an untrusted checkout without explicitly declared top-level permissions; these are repository security-hygiene concerns rather than evidence of package abandonment. The dependency set is moderately broad because the module integrates several translation providers, but it is coherent with the package's documented purpose.

Latest 2.3.1PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

The sole analyzed workflow uses pull_request_target together with an untrusted checkout, a potentially risky CI configuration even though no script injection was detected.

Repo toolingcaution

Composer build tooling is present, but no repository security-scanning tools were detected. The missing security tooling is a hygiene gap, though it is partly weighed against the separate workflow and package-quality evidence.

Security policycaution

No SECURITY.md or equivalent security policy was detected, leaving vulnerability-reporting and response expectations undocumented.

Token permissionscaution

The workflow has no top-level permissions declaration and does not declare read-only permissions, which weakens least-privilege clarity even though no top-level write permissions were observed.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Samuele Martini
Davide Lunardon

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.9
magento/framework
Version *
openai-php/client
Version ^0
deeplcom/deepl-php
Version ^1
magento/module-catalog
Version ^104.0.0

Weekly Downloads

Info

Last Published
14 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform