Package Health

amdeu/typo3-shape

This is a usable but relatively young package with strong recent release activity: six releases over 312 days, the latest published very recently, and the repository is active and not archived. Licensing, package structure, repository linkage, and absence of install-time scripts are reassuring. However, it remains pre-1.0, all 13 commits in the last three months came from one contributor, the repository has no tests or changelog, and there is no security policy or security-scanning tooling. These factors create meaningful maintenance, maturity, and transparency risks, so the package is best adopted with normal dependency monitoring and additional project-level testing.

Latest 0.5.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

A substantial README is present, but neither the artifact nor the repository contains tests or a changelog. For a form-processing extension, the lack of repository tests is a genuine maintenance and regression risk.

Project backingcaution

The repository is owned by a GitHub user rather than an organization, so there is no organizational maintenance backing to offset the single-maintainer concentration.

Repo bus factorcaution

One contributor made all 13 commits in the last three months, giving the project a bus factor of one. The active owner partially compensates for the risk today, but there is no demonstrated contributor redundancy.

Repo commit activitycaution

The repository recorded 13 commits in the last three months, showing current activity, but all activity came from one active maintainer. This combines good recency with a material continuity risk.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little external adoption or review evidence for this young package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^13.4 || ^14.3
—
—
typo3/cms-fluid
Version ^13.4 || ^14.3
—
—
typo3/cms-backend
Version ^13.4 || ^14.3
—
—
typo3/cms-extbase
Version ^13.4 || ^14.3
—
—
typo3/cms-install
Version ^13.4 || ^14.3
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform