Package Health

yireo/magento2-devhacks

Recent commits, a current release, tests, and a security policy support ongoing maintenance. The single active contributor and unpinned container images add adoption and build-reproducibility risk; pin those images before relying on automated builds.

Latest 0.1.3PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

The package has existed for over seven years and released once in the last 12 months, but only four releases overall with a median interval of about 13 months indicate a slow cadence.

Repo bus factorcaution

All five recent commits came from one contributor. Organization ownership offers some handoff capacity, but no second active contributor is shown to reduce immediate concentration risk.

Version stabilitycaution

Version 0.1.3 is not a prerelease, but the 0.x major version signals a less mature compatibility promise than a stable 1.x release.

Workflow auditcaution

All five workflows were analyzed and have no untrusted checkout or script-injection findings, but all six action references are unpinned and two workflows use unpinned or floating-latest container images, creating reproducibility and supply-chain hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jisse Reitsma (Yireo)

Direct Dependencies

DependencyLast ReleaseScore
magento/framework
Version ^100.0|^101.0|^102.0|^103.0
—
—

Weekly Downloads

Info

Last Published
11 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform