Package Health

prestashopcorp/psxmarketingwithgoogle

The project is actively backed by an organization, has recent releases, tests, and a clear package repository. Its release automation still exposes serious control-flow and credential-handling weaknesses, while every analyzed action reference is unpinned.

Latest v1.76.0-beta.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Workflow auditdanger

All 61 analyzed action references are unpinned, and high-confidence findings include template-injection patterns plus checkout credentials persisting into artifacts in build and publish workflows. The audit found no untrusted checkout trigger, but these release-workflow weaknesses remain a substantial supply-chain concern.

Security policycaution

No repository security policy was detected, leaving disclosure and response procedures undocumented.

Version stabilitycaution

This release is a beta and 75% of recent releases are prereleases, so consumers should expect less stability than with a stable release.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
sentry/sentry
Version ^1.11
—
—
vlucas/phpdotenv
Version ^3.4
—
—
brick/phonenumber
Version ^0.4.1
—
—
symfony/polyfill-php80
Version ^1.23.1
—
—
segmentio/analytics-php
Version ^1.5
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform