Package Health

webidea24/magento2-module-widget-add-to-cart

The MIT declaration and small, focused artifact reduce licensing and complexity concerns. Missing consumer documentation, security tooling, and a security policy weaken transparency, while the project shows no demonstrated maintenance capacity beyond its initial release.

Latest 1.0.0PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

This package has only one release, published about 4 years and 5 months ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance for a dependency.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the absence of releases since April 2022. The lack of recent work materially increases abandonment risk.

Package scaffoldingcaution

The artifact has no README, tests, or changelog; missing tests and changelog are normal for published artifacts, but the missing README reduces consumer transparency for a Magento module. The repository does use GitHub Releases, providing only limited documentation compensation.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these very limited adoption signals provide no meaningful external indication of active project backing.

Repo toolingcaution

Composer is used as the build tool, which is appropriate for this package, but no security scanning tools were detected. This is a modest repository hygiene and transparency gap rather than a severe risk by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform