Package Health

oxid-esales/oxideshop-unified-namespace-generator

The organization-backed repository is active, correctly linked, and includes a useful README and tests. Recent work is sparse, this is an alpha release, and the workflow audit found high-confidence injection hygiene concerns.

Latest v8.0.0-alpha.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

All recent commits came from one contributor, creating concentration risk; organization ownership provides some capacity for handoff but no second active contributor is shown.

Repo commit activitycaution

Only 1 commit from 1 active maintainer was recorded in the last 3 months, indicating sparse recent maintenance despite the package's longer release history.

Security policycaution

The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.

Version stabilitycaution

The assessed release is v8.0.0-alpha.2 while the reported latest version is v5.2.1, so this pre-release should be treated as less stable than a mature stable release.

Workflow auditcaution

The sole workflow was fully analyzed and has no dangerous trigger or untrusted checkout, but its only action use is unpinned and it contains a high-confidence template-injection finding; these are meaningful workflow hygiene risks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.14
—
—
composer/composer
Version >=2.0
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform