Package Health

netseu/checkout

Recent releases, four active contributors, release notes, documentation, and tests show substantial ongoing work. Pin the named replacement package rather than starting a new dependency on this one.

Latest 2.4.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names nexi-checkout/shopware6-checkout as its replacement. This is a major adoption risk despite the recent release and active repository.

Repo toolingcaution

The project uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning automation is a modest hygiene concern for a payment integration.

Security policycaution

No repository security policy was found. This reduces transparency for reporting vulnerabilities in a package that handles payment integration, though it is not evidence of abandonment by itself.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkout or script-injection trigger, but both action references are unpinned and high-confidence template-injection findings were reported. These are workflow hygiene and supply-chain concerns, not independently severe enough to determine the score.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nexi|Nets

Direct Dependencies

DependencyLast ReleaseScore
shopware/core
Version ~6.6.0 || ~6.7.0
shopware/storefront
Version ~6.6.0 || ~6.7.0
nexi-checkout/php-payment-sdk
Version ~0.16
giggsey/libphonenumber-for-php-lite
Version ^8.12

Weekly Downloads

Info

Last Published
14 hours ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform