Package Health

cgoit/contao-folder-gallery-bundle

Healthy and actively maintained, with strong documentation, tests, and frequent recent releases. Depend on it with some caution because all recent commits come from one contributor and the release workflow has write permissions without a security policy.

Latest 1.10.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Lifecycle scriptscaution

The package uses post-install and post-update Composer scripts. These increase installation-time activity and deserve review before adoption, although the signal does not show that the scripts are unsafe.

Repo bus factorcaution

All 90 commits in the last three months came from one contributor, giving the project a high single-person dependency despite its strong activity level.

Repo popularitycaution

The repository has 3 stars and no forks or watchers. This is limited adoption evidence, but popularity is supporting evidence and does not outweigh the strong recent maintenance signals.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Token permissionscaution

One workflow, release-please.yml, has top-level write permissions, while the other is read-only. Write access is understandable for automated releases but grants broader automation authority than a fully restricted setup.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Carsten Götzinger

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
contao/image
Version ^1.2
symfony/yaml
Version ^7.3
psr/container
Version ^2.0
symfony/asset
Version ^7.3

Weekly Downloads

Info

Last Published
5 days ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform