Package Health

spryker/product-offer-shipment-type-merchant-portal-gui

This is a healthy, actively maintained release from an organization-backed repository. It has a stable non-prerelease version, recent publishing activity, an unarchived and correctly matching source repository, five active contributors with evenly distributed recent commits, a changelog, license file, and no install-time lifecycle scripts or dangerous workflow patterns. The main reservations are the modest release cadence, absence of repository security scanning and a security policy, and an undelared top-level GitHub Actions token permission policy; these are hygiene gaps rather than evidence of abandonment. The package appears reasonable to depend on, subject to normal review of its proprietary licensing and runtime dependency chain.

Latest 3.1.0PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

The artifact has a README and changelog, and the repository uses GitHub Releases, which supports release transparency. Tests are absent in both the artifact and repository, a modest assurance gap for a UI module, but not by itself evidence of poor maintenance.

Repo toolingcaution

Composer is used as a build tool, providing expected ecosystem tooling. No security scanning tools were detected, which is a security-hygiene gap, though it does not establish abandonment or unsafe behavior by itself.

Security policycaution

No repository security policy was found. This reduces vulnerability-reporting transparency, but the gap is not severe enough to outweigh the active organization-backed maintenance evidence.

Token permissionscaution

The sole workflow does not declare top-level token permissions, so least-privilege intent is not explicit. It has no top-level write permissions, making this a workflow-hygiene caution rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/twig
Version ^3.0.0
—
—
spryker/kernel
Version ^3.30.0
—
—
spryker/zed-ui
Version ^4.3.0
—
—
spryker/symfony
Version ^3.0.0
—
—
spryker/transfer
Version ^3.27.0
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform