Package Health

waaz/sylius-cawl-plugin

No security policy is published, and all seven workflow actions are unpinned; the low-confidence cache warnings are only hygiene concerns. MIT licensing, tests, a recent release, and organization backing provide useful reassurance.

Latest 0.4PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

70

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has four releases over 339 days, with the latest released recently, showing continued maintenance but a relatively slow cadence.

Repo bus factorcaution

All recent repository activity comes from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown.

Repo commit activitycaution

Only one commit was recorded in the last three months, indicating limited recent development activity despite the recent package release.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, so the package-to-repository relationship is not clearly established by the collected evidence.

Security policycaution

The repository has no published security policy, leaving reporting and response expectations unclear for a payment-related plugin.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ibes Mongabure

Direct Dependencies

DependencyLast ReleaseScore
sylius/sylius
Version ~1.14.0
—
—
online-payments/sdk-php
Version ^7.3
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform