Package Health

spryker-eco/punchout-gateway

Version 1.4.0 appears healthy to depend on: the package is actively releasing, stable, non-deprecated, backed by a non-archived organization-owned repository, and has substantial documentation, tests, changelog coverage, and a coherent 222-file implementation with matching repository references. Recent activity includes 15 commits from two active maintainers, two merged pull requests, and a repository update on the assessment date. The main reservations are the absence of a repository security policy and explicit top-level workflow token permissions, plus low repository popularity; these are transparency and governance gaps rather than evidence of abandonment, and the package has no install-time lifecycle scripts or dangerous workflow patterns.

Latest 1.4.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 23 runtime dependencies, reflecting meaningful integration complexity in the Spryker framework. This is a manageable but nontrivial transitive maintenance surface, partially expected for the documented module scope.

Repo popularitycaution

The repository has zero stars, forks, and watchers, so there is little external adoption evidence. Popularity is supporting evidence rather than a verdict, and the active release and commit signals compensate for this gap.

Repo toolingcaution

Composer is used as the build tool, but no security-scanning tool was detected. The build setup is appropriate, while the lack of automated security scanning is a modest governance gap.

Security policycaution

The repository has no SECURITY.md or other detected security policy. This weakens vulnerability-reporting transparency, although it is not evidence of abandonment by itself.

Token permissionscaution

The one CI workflow has no top-level permissions declaration. While no write permissions were detected, explicitly constraining the token would provide stronger least-privilege assurance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/gui
Version ^5.2.2
spryker/log
Version ^3.17.0
spryker/price
Version ^5.0.0
spryker/quote
Version ^2.0.0
spryker/store
Version ^1.19.0

Weekly Downloads

Info

Last Published
13 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform