Package Health

yireo/magento2-checkout-agreement-commands

Documentation and licensing are in place, and the package has a simple runtime dependency with no install-time scripts. Maintenance history is short, and the CI workflows use unpinned container images, so future builds deserve extra scrutiny.

Latest 1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

This release is the package's only release, published about 10 months ago, so there is limited evidence of sustained registry maintenance despite recent repository activity.

Workflow auditcaution

All six action references are unpinned, and two workflows use high-confidence unpinned or floating-latest container images. The audit completed fully and found no untrusted checkout or script-injection paths, but build reproducibility remains weaker.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
magento/framework
Version ^103.0

Weekly Downloads

Info

Last Published
10 months ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform