Package Health

yireo/magento2-googletagmanager2

The module has a long release history, a current stable version, tests, a changelog, and a security policy. Organizational ownership provides some continuity; pin version 3.10.7 and monitor future maintenance.

Latest 3.10.7PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo bus factorcaution

One contributor made all 6 commits in the last 3 months, giving the project a concentrated short-term bus factor. Organizational ownership provides some handoff capacity, but no second recent contributor is shown.

Repo commit activitycaution

The repository received 6 commits in the last 3 months, showing recent maintenance, but all activity came from one active maintainer. The activity is positive while still indicating limited ongoing capacity.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tool was detected. The missing scanner is a modest transparency and maintenance concern, not evidence of abandonment.

Workflow auditcaution

All 5 workflows were analyzed successfully and have no untrusted checkout or script-injection findings, but all 6 action references are unpinned and two workflows use floating or unpinned container images. These high-confidence hygiene issues weaken build reproducibility and supply-chain controls.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jisse Reitsma (Yireo)

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1 || ^2 || ^3
—
—
magento/framework
Version ^102.0 || ^103.0
—
—
magento/module-eav
Version ^100.0 || ^101.0 || ^102.0
—
—
magento/module-tax
Version ^100.0
—
—
magento/module-quote
Version ^101.0
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform