Package Health

warleyelias/ecommerce-module-core

Core component for Pagar.me e-commerce platform modules.

Latest 2.8.2PackagistPackagist

58%

Total Score

caution

Usable with caveats: maintenance has stopped, with no commits or releases for about 14 months.

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months, consistent with the release history showing no releases for about 14 months. This materially raises maintenance and abandonment risk.

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts, adding install-time behavior that users must account for. This is a supply-chain hygiene concern but not severe by itself.

Project backingcaution

The repository is owned by an individual account rather than an organization, so the single registry maintainer does not show broader project backing. This reinforces the thin maintenance picture but is not severe alone.

Release historycaution

The package has only two releases, both effectively published on the same day, and no releases in the last 12 months. This indicates limited release maturity and no recent maintenance evidence.

Repo toolingcaution

Composer build tooling is present, supporting a recognizable build process, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Open Source Team

Direct Dependencies

DependencyLast ReleaseScore
monolog/monolog
Version ^3
—
—
pagarme/pagarmecoreapi
Version v5.6.6
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform