Package Health

cmsexperts/bolt

The repository is intact and the package has a useful README plus release notes for this version. Activity has stopped for over two years, and its publishing workflow has unpinned actions plus a high-confidence template-injection finding.

Latest 2.3.1PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package abandoned at package scope and points developers to b13/bolt as its replacement. This is a severe adoption risk even though the linked repository remains available.

Release historydanger

The last registry release was over two years ago, with no releases in the preceding 12 months. Its earlier history was established, but the current release cadence indicates abandonment risk.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last three months, consistent with the long gap since the latest release. This materially lowers confidence in ongoing maintenance.

Security policycaution

The linked repository has no security policy, leaving vulnerability-reporting and response procedures undocumented. This is a transparency gap, although it is secondary to the package's abandoned status.

Workflow auditcaution

All five analyzed action references are unpinned, and the publishing workflow has a high-confidence template-injection finding. The audit was complete, and the finding affects release-workflow hygiene even without an untrusted checkout or script-injection trigger.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^10.4 || ^11.0 || ^12.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform