Package Health

spryker-demo/product-attribute-set-gui

It has a clear license, a complete source tree, and organization backing. The unpinned CI actions and absent security policy add modest transparency and maintenance concerns.

Latest 1.0.0PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

This 495-day-old package has only one release, with no releases in the last 12 months. That is meaningful evidence of a stalled release cycle, although the stable 1.0.0 version may indicate a small, finished module.

Repo commit activitycaution

The repository recorded no commits and had no active maintainers in the last three months. The recent repository push does not compensate for the lack of observed commit activity in that period.

Security policycaution

The linked repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, though it is a modest concern for this small module rather than evidence of abandonment by itself.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkouts or audit findings, but all four action references are unpinned. This is a reproducibility and maintenance-hygiene gap rather than a severe risk on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/gui
Version ^3.47.1
—
—
spryker/kernel
Version ^3.75.0
—
—
spryker/locale
Version ^3.8.1
—
—
spryker/symfony
Version ^3.11.1
—
—
spryker/translator
Version ^1.9.1
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform