Package Health

overherz/cscartsdk

The stable version, clear README, and declared MIT license support adoption. The single-maintainer project has little visible activity and no security policy, so pin this version only if its current behavior meets your needs.

Latest 1.3.1.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. The repository is owned by an individual rather than an organization, so the thin publisher base provides limited continuity.

Project backingcaution

The registry namespace and repository owner match, and the owner is an individual. This supports package identity but provides no organizational backing to compensate for the small maintainer base.

Release historycaution

The package has 26 releases since June 2019, but none in the last 12 months; its latest release was on October 31, 2023, roughly 3 years before collection. This materially raises abandonment risk.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last 3 months, consistent with a project that is no longer actively maintained.

Repo issue activitycaution

There were no new or closed issues and no pull-request activity in the last month. With no recent commits, this offers no evidence of current maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexander Bolshakov

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^5.2
—
—
symfony/filesystem
Version ~4.0
—
—
symfony/twig-bridge
Version ~4.0
—
—
overherz/upgrade-builder
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform