Package Health

scancode/append-product-stock-now-after-module

The stable version and intact source repository provide some continuity, but the project has little visible support or security process. Treat it as a legacy dependency and prefer an actively maintained alternative if one exists.

Latest v2.0.3PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was published on October 1, 2020, and there have been no releases in the last 12 months. That long period without a release is strong evidence of abandonment risk for a dependency.

Licensecaution

No license is declared, and neither the package nor the linked repository contains a license file. This creates a real legal and reuse risk for adopters.

Maintainerscaution

Only one registry maintainer is listed, leaving a thin publishing base. The linked repository is owned by a user account rather than an organization, so there is no provided backing signal to offset that concentration.

Repo package mentioncaution

The repository name does not match the package name, and the README does not establish that the repository is for this package. That weakens confidence in source transparency, although a subpackage mismatch can occur in ordinary repositories.

Repo toolingcaution

Composer build tooling is present, which supports reproducible package structure, but no security-scanning tooling is reported. This is a modest hygiene gap rather than evidence that the release is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nicolas Widart

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform