Package Health

b13/cta

Its stable release history, clear README, matching repository, and explicit license support adoption. Workflow references are unpinned, and the repository lacks security scanning and a security policy, leaving maintenance and build hygiene concerns.

Latest 2.2.1PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, which is a concrete sign that maintenance may be slowing.

Repo issue activitycaution

No issues or pull requests were opened or closed in the last month, with one issue and one pull request still open; this provides little evidence of active community maintenance.

Repo toolingcaution

Composer is used for builds, but no security scanning tools were detected, leaving a modest gap in repository hygiene.

Security policycaution

The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.

Workflow auditcaution

The single workflow was fully analyzed, but both action references are unpinned and it contains a high-confidence template-injection finding; without an untrusted trigger or checkout this is workflow hygiene risk rather than a severe dependency risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-backend
Version ^10.4 || ^11.0 || ^12.4 || ^13.0 || ^14.0
typo3/cms-fluid-styled-content
Version ^10.4 || ^11.0 || ^12.4 || ^13.0 || ^14.0

Weekly Downloads

Info

Last Published
6 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform