Package Health

codesache/addrelcanonical-bundle

Allow to rel='canonical' entries for glossray-, faq- and news-entries

Latest 1.0.1PackagistPackagist

58%

Total Score

caution

Usable with caveats: no commits or releases for over a year and only one maintainer.

Health Score Breakdown

Maintainerscaution

A single registry maintainer leaves little visible publishing redundancy and creates a thin maintainer base. The linked repository is owned by the same individual, so there is no organizational backing shown to offset that concentration.

Release historycaution

Only two releases were published, both within four days, followed by more than a year without a new release. This suggests limited ongoing maintenance, although the package may be intentionally small and stable.

Repo commit activitycaution

The repository had no commits and no active maintainers in the last three months, consistent with the long release gap. The repository is not archived, which is a modest compensating signal but does not show active upkeep.

Repo toolingcaution

Composer is used for the build, but no security scanning tooling was detected. This is a modest transparency and verification gap rather than evidence of an unsafe release.

Security policycaution

The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This matters for a framework integration package, though it is not severe on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andreas Fieger

Direct Dependencies

DependencyLast ReleaseScore
contao/core-bundle
Version ^4.13 || ^5.3
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform