Package Health

spryker-feature/tax

The package is straightforward to consume, with no install-time scripts and clear installation guidance. Its workflow audit found no high-risk patterns, though all four referenced actions are unpinned.

Latest 202608.0PackagistPackagist

79%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo bus factorcaution

One contributor, the release bot, made all four recent commits, so direct recent contributor diversity is low. Organization ownership provides some ability to hand maintenance off, making this a caution rather than a severe abandonment signal.

Repo toolingcaution

The project uses Composer for builds, but no security-scanning tools were detected. The missing scanning is a modest transparency and hygiene gap, not evidence of unsafe code.

Security policycaution

The repository has no security policy. This limits published guidance for reporting and handling vulnerabilities, but it does not by itself indicate that maintenance has stopped.

Workflow auditcaution

The sole workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. However, all four action references are unpinned, leaving them exposed to upstream changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/tax
Version ^5.19.0
—
—
spryker/tax-storage
Version ^1.8.0
—
—
spryker/tax-product-storage
Version ^1.9.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform