Package Health

spryker/product-merchant-portal-gui

Healthy and suitable to use. It has frequent releases, current repository activity from eight contributors, strong package structure and tests, with only modest transparency concerns around missing security policy and unspecified workflow token permissions.

Latest 5.5.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The module declares 36 runtime dependencies, which is substantial, but they are largely related Spryker platform components expected for a merchant-portal GUI module; this increases upgrade coupling without indicating abandonment.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected; this is a modest assurance gap, not a severe health problem given the active repository and CI workflow.

Security policycaution

The repository has no SECURITY.md or equivalent security policy, leaving vulnerability reporting and response expectations undocumented.

Token permissionscaution

The CI workflow does not declare top-level token permissions. No write permissions were observed, but the absence of an explicit read-only policy weakens workflow hardening.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/gui
Version ^3.48.0 || ^4.0.0 || ^5.0.0
spryker/oms
Version ^11.7.0
spryker/twig
Version ^3.29.0
spryker/money
Version ^2.0.0
spryker/stock
Version ^8.14.0

Weekly Downloads

Info

Last Published
7 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform