Package Health

serhiikamolov/laravel-shopify

The repository includes tests and a changelog, but no security policy or automated security scanning. Its workflows leave all six actions unpinned, adding maintenance hygiene risk.

Latest v1.2.8PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This is the package's only release, published about 19 months ago, with no releases in the last 12 months. That leaves maintenance continuity and future support uncertain.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the one-release history and raising abandonment risk.

Repo popularitycaution

The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external sign of adoption or review.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured. The missing automated security check is a modest transparency and maintenance gap.

Security policycaution

The linked repository has no security policy. For a package handling Shopify API communication and webhooks, this reduces transparency around vulnerability reporting and response.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Morten Poul Jensen

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^8.0|^9.0|^10.0|^11.0
—
—
guzzlehttp/guzzle
Version ^7.2
—
—
illuminate/routing
Version ^8.0|^9.0|^10.0|^11.0
—
—
illuminate/support
Version ^8.0|^9.0|^10.0|^11.0
—
—
illuminate/contracts
Version ^8.0|^9.0|^10.0|^11.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform