Package Health

spryker/merchant-relationship-merchant-portal-gui

This release appears healthy and suitable to depend on: it is a stable, non-deprecated 2.2.0 release with recent publication activity, an active unarchived repository, six commits from six maintainers in the last three months, and strong organization backing from Spryker. The package and repository are structurally consistent, include README and changelog documentation, and use a normal Composer build path without install-time lifecycle scripts. The main reservations are that neither the artifact nor repository contains tests, the repository has no declared security policy or security-scanning tooling, and its CI workflow does not declare top-level token permissions; these are meaningful hygiene gaps but do not outweigh the evidence of current maintenance and coherent ownership.

Latest 2.2.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

README and changelog documentation are present in both the package context and repository, but tests are absent from both. For a framework GUI module this is a real verification gap, though the documentation and repository-backed structure provide some compensation.

Repo issue activitycaution

There were no new or closed issues and no pull requests in the last month; this gives little evidence of active community support. However, the absence of issue activity is partly offset by recent commits from multiple maintainers.

Repo popularitycaution

The repository has zero stars and forks and four watchers. This is weak community adoption evidence, but popularity is supporting evidence only and the organization-backed maintenance signals are more relevant here.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools were detected. The standard build tooling is appropriate, while the missing security scanning is a repository hygiene gap.

Security policycaution

No repository security policy was found. This reduces vulnerability-reporting transparency, although it is a hygiene concern rather than evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/twig
Version ^3.0.0
—
—
spryker/kernel
Version ^3.30.0
—
—
spryker/zed-ui
Version ^4.3.0
—
—
spryker/symfony
Version ^3.0.0
—
—
spryker/transfer
Version ^3.27.0
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform