Package Health

acclaro/translations

This is a mature, actively published Craft CMS plugin with 122 releases over roughly 7 years, 14 releases in the last 12 months, a stable non-prerelease version, an unarchived organization-owned repository, documented tests and changelog, and no install-time lifecycle scripts. The main concern is that the repository recorded no commits or active maintainers in the last 3 months, despite six merged pull requests in the last month, so maintenance activity is somewhat inconsistent. Missing security-policy coverage, limited repository popularity, and permissive or absent workflow token-hardening reduce transparency and operational confidence, but do not outweigh the strong release history and project backing.

Latest v4.2.7PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitycaution

There were zero commits and zero active maintainers in the last 3 months, which is a genuine maintenance concern; the six merged pull requests in the last month partly compensate but do not fully establish ongoing commit activity.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The absence of scanning lowers security-process transparency, though it is not by itself evidence of unhealthy maintenance.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap for a production plugin.

Token permissionscaution

One workflow lacks top-level permissions and another declares top-level write access, so workflow token scope is not consistently minimized. This is a repository-hygiene concern, although dangerous workflow patterns were not detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Acclaro

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^5.9.22
—
—
composer/composer
Version ^2.9.3
—
—
guzzlehttp/guzzle
Version ^7.0
—
—
google/cloud-translate
Version ^1.15
—
—
spatie/guzzle-rate-limiter-middleware
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform