Package Health

sas/esd

Usable with caveats: the repository is active, organized, and backed by an organization, but version 2.0.0 has had no registry release for nearly three years. Missing security documentation and workflow permission declarations add smaller transparency concerns.

Latest 2.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historycaution

The package has 30 releases and a historically regular median interval of about 14 days, but the latest registry release was on 2023-10-07 and there were no releases in the following 12 months. This is a meaningful release-maintenance concern, partly offset by recent repository commits.

Repo toolingcaution

The repository uses Composer and Make for build-related work, supporting repeatable project maintenance, but no security scanning tools were detected.

Security policycaution

No repository security policy was found. This is a transparency gap for a plugin handling customer downloads, although it is not evidence that the package is unsafe.

Token permissionscaution

Both analyzed workflows lack top-level token permission declarations. No workflow requests top-level write access, which limits the concern, but explicit least-privilege settings would improve CI transparency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Shape & Shift

Direct Dependencies

DependencyLast ReleaseScore
shopware/core
Version ~6.5.2
—
—
shopware/storefront
Version ~6.5.2
—
—
shopware/administration
Version ~6.5.2
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform