Package Health

shopwell/production

The repository has only one recent contributor, and the release history is too new to establish a stable maintenance pattern. Install-time scripts and a workflow with broad write access and an unpinned action add modest operational risk, while organization backing and clear licensing help.

Latest v6.7.15.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts, increasing the amount of code executed during dependency operations and adding operational supply-chain exposure.

Package file treecaution

The small artifact includes .env and .env.local files, which is unusual packaging hygiene for a dependency and warrants checking that they contain no environment-specific or sensitive content.

Release historycaution

The package is only 0 days old with three releases published within roughly 2 hours, so there is not yet enough history to demonstrate durable maintenance or release stability.

Repo bus factorcaution

All recent commit activity is concentrated in one contributor. The organization-owned repository provides some ability to hand off maintenance, but no second active contributor is evidenced.

Repo commit activitycaution

Only one commit from one active maintainer was recorded in the last 3 months, providing very limited evidence of sustained maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/flex
Version ~2
—
—
shopwell/platform
Version v6.7.15.0
—
—

Weekly Downloads

Info

Last Published
4 hours ago
Created
20 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform