Package Health

webmenedzser/uvb-connector-woocommerce

This release appears usable and actively maintained: it has a long release history, frequent recent releases, a stable non-prerelease version, an unarchived organizational repository, clear licensing, and no install-time lifecycle scripts. The main concerns are that all 17 recent commits came from one contributor, the repository does not name or mention the Packagist package, no security scanning or security policy is present, and the release workflow grants top-level write permissions. These issues reduce transparency and resilience, but the observed release and repository activity provide meaningful compensation, so this is a cautionary rather than unhealthy dependency.

Latest 4.3.6PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Package scaffoldingcaution

A substantial README is present and the repository uses GitHub Releases, but neither the artifact nor repository contains tests or a changelog. Those omissions reduce transparency somewhat for a production integration plugin.

Repo bus factorcaution

One contributor made all 17 commits in the last 3 months, producing a top-contributor share of 100%. Despite organizational ownership, this remains a meaningful continuity risk because no second contributor is currently active.

Repo issue activitycaution

There are no open issues and two open pull requests, but no issues or pull requests were merged in the last month. This is a limited concern because commit activity remains active.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. This weakens confidence that the linked repository is transparently tied to this release, although the repository path is still semantically related to the WooCommerce connector.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these very low figures provide little external validation.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Utánvét Ellenőr

Direct Dependencies

DependencyLast ReleaseScore
utanvet-ellenor/client-php
Version ^2.1.0
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform