Package Health

shopware/dev-tools

The MIT license, clear README, active repository, and organization backing support dependable use. Maintenance is currently quiet, with no commits or active maintainers in the last three months, despite the 1.6.0 release.

Latest 1.6.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Dependency profilecaution

This is a Composer development meta-package with 8 declared runtime dependencies, including PHPUnit and Symfony tooling. The dependency bundle is broad, so adopters inherit several upstream maintenance surfaces, but that is consistent with its stated purpose.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. The 1.6.0 release and recent repository push partly offset this, but the lack of recent development is a maintenance caution.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and assurance gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, which modestly lowers project transparency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
fakerphp/faker
Version ^1.20
—
—
phpunit/phpunit
Version ^9.6 | ^10 | ^11.4 | ^12 | ^13
—
—
symfony/browser-kit
Version ^5.4 | ^6 | ^7
—
—
doctrine/sql-formatter
Version ^1.1
—
—
symfony/doctrine-bridge
Version ^5.4.7 | ^6 | ^7
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform