Package Health

zero1/open-pos-default-payments

This is a small but currently maintained Magento package with a stable 1.0.2 release, a non-archived repository updated alongside the latest release, two active contributors with balanced commit share, and three merged pull requests in the last month. Its license, compact dependency profile, and absence of install-time scripts are positive indicators. However, the package is only 215 days old with three releases, has no tests or changelog in either artifact or repository, lacks a security policy and security-scanning tooling, and the linked repository neither matches the package name nor mentions it in its README, which creates a meaningful transparency concern. It appears usable, but dependency adoption should include verification that the repository is the intended source and additional project-level testing.

Latest 1.0.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The package has a README, but neither the artifact nor repository contains tests or a changelog. For a payment module, the absence of repository tests is a genuine maintenance and verification gap.

Release historycaution

The package is relatively young at 215 days and has only three releases, with a median interval of about 108 days. This is limited maturity evidence rather than abandonment, because the latest release was published recently.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Although name differences can occur with subpackages, the combination creates a meaningful risk that the linked repository is not clearly the package's intended source.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools are present. The missing scanning is a transparency and hygiene gap, though it is not by itself evidence of unsafe code.

Security policycaution

No SECURITY.md or equivalent security policy was found, leaving vulnerability reporting and response expectations unclear.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
magento/framework
Version ^100.1|^101.0|^102.0|^103.0

Weekly Downloads

Info

Last Published
18 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform