Package Health

vrpayment/shopware-6

This release appears usable and generally healthy: it has a stable version, 31 releases over roughly 19.5 months, 24 releases in the last 12 months, recent publication, an active non-archived organization-owned repository, a matching package repository, clear licensing, documentation, and no install-time lifecycle scripts. The main concerns are limited recent repository activity—only 2 commits from 1 contributor in the last 3 months—along with no repository security scanning, no security policy, no tests in either the artifact or repository, and very low repository popularity. These issues increase maintenance and assurance risk, but the frequent release cadence, organization backing, changelog, and current repository state provide meaningful compensation.

Latest 7.3.7PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package has 8 runtime dependencies, including Shopware components and its SDK; this is a meaningful integration surface but not unusually broad for a Shopware payment plugin.

Package scaffoldingcaution

A substantial README and changelog are present, and repository releases are used; tests are absent from both the artifact and repository, which leaves a genuine verification gap for this payment integration.

Repo bus factorcaution

All 2 recent commits came from one contributor, creating a concentrated bus factor. Organization ownership partially compensates because maintenance can potentially be handed off internally, but no second active contributor is shown.

Repo commit activitycaution

Only 2 commits were recorded in the last 3 months, all from one active maintainer. This is notably thin recent development activity despite the strong registry release cadence.

Repo issue activitycaution

There were no new issues or pull requests and no merged pull requests in the last month; this is limited evidence of community activity, though the absence of issues is not by itself evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

VR Payment

Direct Dependencies

DependencyLast ReleaseScore
shopware/core
Version ~6.7.0
vrpayment/sdk
Version ^4.8.1
shopware/storefront
Version ~6.7.0
shopware/administration
Version ~6.7.0

Weekly Downloads

Info

Last Published
10 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform