Package Health

webkul/code-generator

The package includes clear usage documentation, a release note, and no install-time scripts. Its license metadata conflicts with the MIT license file, while security scanning is absent and the workflow uses an unpinned action.

Latest 2.0.8PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Licensecaution

The artifact includes an MIT license file, but the manifest declares the package as proprietary. That mismatch creates avoidable licensing uncertainty for adopters.

Release historycaution

The package has had no releases in more than two years, despite ten releases overall; this is meaningful evidence of reduced maintenance for a Magento development tool.

Repo commit activitycaution

There were no commits or active maintainers in the measured three-month window, reinforcing the concern that maintenance has slowed substantially.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. This weakens repository transparency and automated assurance without proving the package is unsafe.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers or audit findings, but its only action use is unpinned. The missing top-level permissions block is acceptable on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform