Package Health

aoepeople/crawler

The repository is active, documented, licensed, and has three recent contributors. Workflow references are all unpinned, with one high-confidence template-injection warning; the package also runs an install-time script.

Latest 12.0.11PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package abandoned, although the replacement points to the same package. This is a meaningful maintenance and adoption warning, but it is partly offset by recent releases and repository activity.

Lifecycle scriptscaution

A post-autoload-dump install-time script runs during Composer setup. This adds execution complexity for consumers, but the signal provides no evidence that the script is unsafe.

Project backingcaution

The repository is owned by an individual account rather than an organization account, so the package's two registry maintainers do not provide strong evidence of organizational handoff capacity.

Workflow auditcaution

All 12 workflows were analyzed without failures, but all 53 action references are unpinned. The audit also found a high-confidence template-injection warning and a low-confidence cache-poisoning warning; without dangerous triggers, these are workflow hygiene concerns rather than standalone severe risks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tomas Norre Mikkelsen

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
—
—
doctrine/dbal
Version ^3.10 || ^4.3
—
—
typo3/cms-seo
Version ^12.4 || ^13.4
—
—
typo3/cms-core
Version ^12.4 || ^13.4
—
—
typo3/cms-info
Version ^12.4 || ^13.4
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform