Package Health

area17/twill

Healthy and suitable to use, with some maintenance caveats. It has a long release history, an active organization-backed repository, tests and release notes, but recent commits are concentrated in one contributor and issue resolution has been quiet.

Latest 3.6.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The package declares 19 runtime dependencies, including framework, storage, analytics, and authentication integrations. This breadth increases upgrade and compatibility surface, but is plausible for a full CMS toolkit and is not itself evidence of abandonment.

Lifecycle scriptscaution

The package runs a post-autoload-dump script during installation. This is an operational consideration because dependency installation executes package code, but the signal alone does not indicate abandonment or poor maintenance.

Repo bus factorcaution

All 5 commits in the last 3 months came from one contributor, creating a current concentration risk. Organization backing provides some ability to hand off maintenance, so this is a caution rather than a severe abandonment signal.

Repo commit activitycaution

The repository received 5 commits in the last 3 months, so activity has not stopped, but the volume is modest for a substantial framework package.

Repo issue activitycaution

There were no new or closed issues in the last month and no merged pull requests, while 2 pull requests were opened. This indicates some current activity but limited recent resolution of outstanding work.

Vulnerabilities

TitleVersionsSeverity
CVE-2021-3932
area17/twill is vulnerable to Privilege Chaining in versions 0.0.0 - 1.2.5 and 2.0.0 - 2.5.3.
0.0.0 - 1.2.52.0.0 - 2.5.3
Medium

Package versions

Maintainers

AREA 17

Direct Dependencies

DependencyLast ReleaseScore
laravel/ui
Version ^4.0
spatie/once
Version ^3.0
doctrine/dbal
Version ^3.0 || ^4.0
imgix/imgix-php
Version ^3.0
kalnoy/nestedset
Version ^6.0 || ^7.0

Weekly Downloads

Info

Last Published
2 months ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform