Package Health

reach-digital/magento2-vendit

Clear installation guidance and a stable release history support adoption. Organization backing and a documented repository add useful context, but the project remains young and has limited operational maturity.

Latest v1.1.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

The package declares no license, contains no license file, and the repository has no license file. That leaves usage and redistribution rights unclear for a Magento integration.

Repo bus factorcaution

One contributor made all 8 commits in the last 3 months, creating a high single-maintainer dependency. Organization ownership provides some handoff potential, but no second active contributor is shown.

Repo commit activitycaution

The repository recorded 8 commits in the last 3 months, showing recent maintenance. All activity comes from one maintainer, so ongoing maintenance capacity is limited.

Repo toolingcaution

The repository uses Composer for builds, which fits the package ecosystem, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.

Security policycaution

The repository has no security policy. For an integration that handles orders, customers, inventory, and webhooks, the absence of a documented vulnerability-reporting process lowers operational maturity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
honl/magento2-import
Version ^1.3
—
—
magento/product-community-edition
Version ^2.4
—
—
opengento/module-category-import-export
Version ^0.5.6
—
—
ampersand/magento2-disable-stock-reservation
Version ^1.3
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform