Package Health

yireo/yireo_serverpush

The renamed source is active, tested, licensed, and backed by an organization, but all recent commits come from one contributor. Workflow images are also unpinned, weakening build reproducibility.

Latest 1.4.25PackagistPackagist

24%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package abandoned and names yireo/magento2-serverpush as its replacement. This directly makes the assessed package unsuitable for a new dependency despite other healthy project evidence.

Repo bus factorcaution

One contributor made all 5 commits in the last 3 months, leaving maintenance dependent on a single active contributor. Organization backing partly compensates for this concentration, but continuity risk remains.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The available build tooling is useful, while the missing scanning is a modest transparency gap.

Workflow auditcaution

All 5 workflows were analyzed without failures and have no untrusted checkout or script-injection findings. However, all 6 action references are unpinned and four high-confidence findings identify unpinned or floating container images, creating reproducibility and supply-chain hygiene risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jisse Reitsma (Yireo)

Direct Dependencies

DependencyLast ReleaseScore
magento/framework
Version ^102.0|^103.0
—
—
symfony/dom-crawler
Version ^2.7|^3.0|^4.0|^5.0|^6.0|^7.0
—
—
magento/module-store
Version ^100.0|^101.0
—
—
magento/module-config
Version ^100.0|^101.0
—
—
magento/module-backend
Version ^101.0|^102.0
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform