Package Health

seiger/scommerce

Healthy and actively maintained, with strong release and commit activity and a clear repository match. Review the install script and workflow permissions before adopting, and note the small maintainer base and lack of a security policy.

Latest v1.3.11PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script. This adds install complexity and should be reviewed, although the signal does not show a destructive or clearly unsafe action.

Project backingcaution

The package and repository are owned by the same named individual, but the repository owner is a user rather than an organization. This supports clear ownership while offering less institutional continuity.

Repo bus factorcaution

The top contributor made 72% of recent commits, creating some concentration risk, but two other contributors were active and one supplied 26% of commits. This is a maintenance concern rather than a severe single-person failure risk.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency gap for a package handling e-commerce functionality, though it is not evidence of maliciousness.

Security policycaution

No repository security policy was found. This makes vulnerability reporting and maintenance expectations less transparent.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Serhii Korneliuk

Direct Dependencies

DependencyLast ReleaseScore
dmi3yy/ddocs
Version ^1.0
—
—
seiger/stask
Version ^2.0
—
—
seiger/sgallery
Version ^1.5
—
—
evolution-cms/evolution
Version ^3.5.8
—
—

Weekly Downloads

Info

Last Published
9 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform