Package Health

omikron/shopware6-factfinder

Documentation, a changelog, and release notes make integration and version changes clear. Organization backing, active repository tooling, and a license file provide useful support despite limited recent contributor breadth.

Latest v7.4.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

All eight recent commits came from one contributor, leaving maintenance dependent on a single active individual. Organization backing partly mitigates handoff risk but does not remove the concentration.

Repo commit activitycaution

The repository recorded eight commits in the last three months, showing ongoing work, but only one active maintainer contributed them.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.

Version stabilitycaution

The release is marked stable and not prerelease, which supports dependable adoption. However, the reported latest version is v5.4.2 while the assessed release is v7.4.0, an inconsistency that reduces confidence in the metadata.

Workflow auditcaution

The single workflow was fully analyzed with no reported dangerous findings or untrusted checkout, but all three action references are unpinned, weakening build reproducibility and action supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Omikron Data Quality GmbH

Direct Dependencies

DependencyLast ReleaseScore
shopware/core
Version ~6.7.0
shopware/storefront
Version ~6.7.0
league/flysystem-ftp
Version ^3.0
league/flysystem-sftp-v3
Version ^3.0
salesforce/handlebars-php
Version 3.*

Weekly Downloads

Info

Last Published
1 month ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform