Package Health

zero-to-prod/spapi-lwa-sdk

A Software Development Kit for connecting to Amazons Selling Partner API with Login With Amazon (LWA).

Latest v1.1.0PackagistPackagist

44%

Total Score

unhealthy

Risky: no release in over a year, no recent commits, and workflow injection findings weaken maintenance and supply-chain confidence.

Health Score Breakdown

Release historydanger

Only three releases have been published, with no releases in the last 12 months and the latest release over a year ago. This is meaningful evidence of stalled maintenance for a package intended as an SDK.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, leaving current maintenance capacity unclear and increasing abandonment risk.

Workflow auditcaution

All seven analyzed action references are unpinned, and the audit found a high-confidence script-injection issue plus high-confidence template-injection findings in annotate.yml. The absence of pull_request_target and workflow_run triggers limits the risk, but the workflow still needs remediation.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

David Smith

Direct Dependencies

DependencyLast ReleaseScore
zero-to-prod/arr
Version ^1.0
—
—
zero-to-prod/spapi-lwa
Version ^4.0
—
—
zero-to-prod/data-model
Version ^81.9
—
—
zero-to-prod/transformable
Version ^71.0
—
—
zero-to-prod/curl-helper-sdk
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform