Package Health

tagginggroup/gtm

This release appears generally suitable to depend on: it is actively released, with 32 releases over 828 days and 13 releases in the last 12 months, is stable and not deprecated, has an identified organization-owned repository, tests, a license file, and recent activity from two maintainers. The main concerns are transparency and repository linkage: the linked repository neither matches the package name nor mentions it in its README, and the repository lacks a security policy, security-scanning tooling, and explicit top-level workflow permissions. These issues warrant review of provenance and CI configuration, but they do not outweigh the strong release and maintenance evidence.

Latest 1.9.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo package mentioncaution

The repository name does not match tagginggroup/gtm and its README does not mention the package, creating a provenance and package-to-repository linkage concern despite the ordinary possibility of a related Magento repository.

Repo popularitycaution

The repository has zero stars and two forks, providing little external adoption evidence; popularity is supporting evidence only, so this is a modest concern rather than a health verdict.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap in the repository.

Security policycaution

No repository security policy was found, which reduces transparency for vulnerability reporting and response.

Token permissionscaution

The sole workflow lacks top-level GitHub Actions permissions, so its effective permissions are not explicitly constrained in the repository metadata.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jeroen Frenken (AdPage)
Jisse Reitsma (Yireo) (Original author do not contact)

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1 || ^2 || ^3
magento/framework
Version ^102.0 || ^103.0
magento/module-eav
Version ^100.0 || ^101.0 || ^102.0
magento/module-quote
Version ^101.0
magento/module-sales
Version ^100.0 || ^101.0 || ^102.0 || ^103.0

Weekly Downloads

Info

Last Published
12 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform