Package Health

qingwuit/qwshop

laravel+vue for b2b2c.

Latest v3.8.6PackagistPackagist

57%

Total Score

caution

Usable with caveats: maintenance stopped after October 2024 and the license metadata conflicts.

Health Score Breakdown

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last 3 months; together with the old latest release, this points to stalled maintenance.

Licensecaution

The artifact declares MIT and includes license files, so it is not unlicensed, but detected Apache-2.0 text conflicts with the declaration and requires legal clarification.

Lifecycle scriptscaution

The package runs four Composer lifecycle hooks, including post-install and post-update actions; these are operationally significant because installation executes package-provided code.

Release historycaution

The package has 97 releases since March 2021, but none in the last 12 months and its latest release was over 1 year ago, indicating a meaningful maintenance gap.

Security policycaution

The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package that supports payments and user accounts.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
yansongda/pay
Version ~3.1
—
—
laravel/tinker
Version ^2.5
—
—
laravel/sanctum
Version ^2.11
—
—
laravel/passport
Version ^10.1
—
—
guzzlehttp/guzzle
Version ^7.0.1
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform