Package Health

brotkrueml/coordconverter

A single publisher and no security policy limit resilience if the maintainer steps away. The license, release notes, tests, documentation, and non-archived repository provide useful adoption support.

Latest v3.4.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

Only one registry account has publishing access, leaving a thin release-publishing base. The linked repository shows an identifiable individual owner, but that does not provide the resilience of a broader maintainer team.

Release historycaution

The package has existed since 2018, but only one release appeared in the last 12 months and releases are typically about eight months apart. The recent v3.4.0 release provides some evidence of continued maintenance, but the cadence is slow.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. This is a meaningful sign of slowed maintenance, although the recent release and repository push provide partial compensation.

Security policycaution

The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, with no provided compensating security process.

Workflow auditcaution

Both workflows were analyzed successfully with no untrusted checkouts, script injection, or high-confidence audit findings. However, all seven referenced actions are unpinned, leaving avoidable build-integrity exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Chris Müller

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^12.4 || ^13.4 || ^14.0
typo3/cms-fluid
Version ^12.4 || ^13.4 || ^14.0

Weekly Downloads

Info

Last Published
9 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform