Package Health

21torr/storyblok

This is a healthy, actively maintained Symfony integration package with a strong release cadence, a stable non-prerelease version, complete basic project documentation and testing scaffolding, and a recently updated, non-archived organization-owned repository. The main concerns are that 83% of recent commits come from one contributor, the repository has no security policy, and its CI workflow declares no top-level token permissions. These are meaningful hygiene and continuity risks, but they are outweighed by 24 commits from four contributors in the last 3 months, 36 releases in the last 12 months, active pull-request merging, and the organization backing. It appears reasonable to depend on, with normal review of its relatively broad runtime dependency set.

Latest 5.3.4PackagistPackagist

85%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 28 runtime dependencies, including a broad Symfony and 21TORR component set; this increases transitive maintenance surface, although it is consistent with a feature-rich Symfony bundle.

Repo bus factorcaution

The leading contributor made 20 of 24 recent commits, an 83% share, creating concentration and continuity risk; three additional contributors remain active, and organization ownership provides some ability to hand off maintenance.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected; the missing automated security tooling is a modest transparency gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented; this is a genuine security-maintenance hygiene gap.

Token permissionscaution

The only workflow, .github/workflows/ci.yml, declares no top-level token permissions. Although no top-level write permissions were detected, explicit least-privilege configuration would provide stronger CI transparency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

21TORR

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
21torr/cli
Version ^1.3
—
—
21torr/snail
Version ^1.0.2
—
—
symfony/lock
Version ^8.0
—
—
21torr/hosting
Version ^4.2.1
—
—

Weekly Downloads

Info

Last Published
22 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform