Package Health

myparcelnl/magento

This is a healthy, mature release with a long release history, frequent recent releases, stable versioning, active organizational backing, and a repository that is current, correctly associated with the package, and supported by tests, documentation, a changelog, and reproducible Composer tooling. The main concerns are transparency and operational hygiene: the repository has 91 open issues with no issues closed in the last month, lacks a security policy and automated security scanning, and its four workflows do not declare top-level token permissions. These issues warrant review before adoption but do not outweigh the package's sustained maintenance and strong project structure.

Latest 5.10.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo issue activitycaution

There are 91 open issues and no issues closed in the last month, although two pull requests were opened and two merged during that period. The pull-request activity is encouraging, but the unresolved issue backlog is a maintenance-hygiene concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanning coverage is a supply-chain hygiene gap, though it is not evidence of a malicious package.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and coordinated-disclosure guidance unspecified. This is a transparency gap for a package that integrates with Magento and external services.

Token permissionscaution

All four workflows lack top-level GitHub Actions permissions declarations. Although none declares top-level write permissions, explicitly setting least-privilege permissions would provide stronger workflow hardening and transparency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joeri van Veen
Richard Perdaan

Direct Dependencies

DependencyLast ReleaseScore
myparcelnl/sdk
Version 11.0.0-beta.15@beta
guzzlehttp/guzzle
Version ^7.0
magento/framework
Version >=101.0.8 <102 || >=102.0.1

Weekly Downloads

Info

Last Published
13 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform