Package Health

spryker/dashboard-merchant-portal-gui

This is a healthy, actively maintained release with a substantial history since 2020, a stable non-prerelease version, a current non-archived organization-owned repository, and recent activity from six contributors. The package and repository contain coherent source, changelog, license, CI, and build structure, with no install-time lifecycle scripts or dangerous workflow patterns. The main cautions are the absence of tests in both the artifact and repository, no detected security scanning or security policy, and a CI workflow without explicitly declared top-level token permissions; these are meaningful hygiene gaps but do not outweigh the strong maintenance, backing, release, and repository evidence.

Latest 4.2.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

A README and changelog are present, and the repository uses GitHub Releases, which supports transparency. Tests are absent from both the artifact and repository, leaving a genuine validation gap for this application module.

Repo popularitycaution

The repository has zero stars and forks and six watchers. Low popularity is a weak caution for external visibility, but it is outweighed here by recent commits and organization backing.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The build structure is positive while security-process visibility remains a hygiene gap.

Security policycaution

No repository security policy was found, reducing transparency about vulnerability reporting and response procedures.

Token permissionscaution

The only workflow lacks top-level token permissions, so least-privilege intent is not explicitly declared. No workflow is shown to request top-level write permissions, limiting the severity of this gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/kernel
Version ^3.33.0
spryker/zed-ui
Version ^4.3.0
spryker/symfony
Version ^3.0.0
spryker/transfer
Version ^3.27.0
spryker/acl-merchant-portal-extension
Version ^1.0.0

Weekly Downloads

Info

Last Published
15 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform