Package Health

bartacus/platformsh-bundle

This is a mature, stable package with a long release history, five releases in the last 12 months, a recent release, an explicit GPL license, no registry deprecation, no install-time lifecycle scripts, and organization backing. However, the linked repository shows only two commits from one active contributor in the last three months, has no tests, no security scanning or security policy, and does not match or mention the package name, which raises maintenance and repository-association concerns. It appears usable, but dependency adoption should include continued monitoring of repository ownership and maintenance activity.

Latest 6.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Package scaffoldingcaution

A README and changelog are present, and the repository uses GitHub Releases, but neither the artifact nor repository contains tests. For a small integration bundle this is a genuine verification gap, though documentation and release hygiene partly compensate.

Repo bus factorcaution

All recent commits came from one contributor, giving a 100% top-contributor share. Organization ownership provides some ability to transfer maintenance, but no second active contributor is evidenced in this period.

Repo commit activitycaution

Only 2 commits were recorded in the last 3 months, from 1 active maintainer. Recent activity exists, but its low volume is a caution for a dependency that may need timely fixes.

Repo package mentioncaution

The repository name does not match the package name and the README does not mention the package. Because this is more than an ordinary subpackage naming mismatch, the linkage between the published package and repository warrants verification.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are detected. The build setup is appropriate, while the missing security automation is a transparency and maintenance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Stefan Herndler
Simon Kendler
pixelart GmbH

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^14.3
—
—

Weekly Downloads

Info

Last Published
25 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform