Package Health

shopify/shopify-app-php

This is a healthy, actively maintained release with strong transparency and organizational backing. It has a clear MIT license, a substantial README and changelog, a matching source repository, regular releases over the past 237 days, recent repository activity, and no deprecation or archival indicators. The main concerns are the absence of tests in both the package and repository, no detected security-scanning tooling, and several workflows declaring top-level write permissions; these are meaningful hygiene gaps but are partly outweighed by the active Shopify organization ownership, current development, security policy, and otherwise coherent package structure.

Latest v1.0.2PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dangerous workflowscaution

Two workflows use pull_request_target and one uses workflow_run, which warrants review of privileged CI paths. However, no untrusted checkouts or script-injection patterns were detected, limiting the health impact.

Package scaffoldingcaution

The package has a substantial README and changelog, but neither the artifact nor repository contains tests. For a security-sensitive application library, the lack of visible tests is a maintenance and regression-risk concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. For a package handling authentication and tokens, this is a security-process hygiene gap, though it does not by itself establish abandonment or unsafe code.

Token permissionscaution

All four workflows declare top-level permissions, but three grant top-level write permissions and only one is read-only. Explicit permissions are better than omission, yet broad write access remains a CI hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
firebase/php-jwt
Version ^7.0
—
—
guzzlehttp/guzzle
Version ^7.0 || ^8.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform