Package Health

shipstream/openmage-sync

ShipStream Sync Extension for Magento 1 and OpenMage

Latest 1.3.0PackagistPackagist

58%

Total Score

caution

Usable with caveats: no release in over a year and no recent repository commits make maintenance uncertain.

Health Score Breakdown

Licensecaution

The artifact contains a license file, but it is detected as MIT while the manifest declares OSL-3.0. That mismatch creates a real licensing ambiguity for adopters.

Release historycaution

The package has five releases since December 2021, but none in the last 12 months; the latest release was about 17 months ago. This indicates materially slowed maintenance despite a previously regular cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long gap since the latest release. The repository is not archived, but recent maintenance capacity is currently unclear.

Workflow auditcaution

The single workflow was fully analyzed and has no untrusted checkouts or script injection, but both action references are unpinned and one uses an archived action. These are supply-chain hygiene weaknesses, not a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

ShipStream

Direct Dependencies

DependencyLast ReleaseScore
magento-hackathon/magento-composer-installer
Version *
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform