Package Health

con4gis/reservation

This is a mature, actively maintained and transparently published package: it has been released for over 6 years, has 224 releases including 53 in the last 12 months, is not deprecated, and the linked organization-owned repository is not archived and was updated recently. The main concerns are that all 73 commits in the last 3 months came from one contributor, the artifact and repository contain no tests or changelog, and the repository lacks a security policy while its workflow does not declare top-level permissions. These are meaningful hygiene and continuity risks, but they are outweighed by the strong release cadence, stable versioning, organization backing, licensing, repository tooling, and absence of dangerous workflow patterns.

Latest v4.2.20PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

A substantive README documents features, installation, requirements, and update considerations, but neither the artifact nor repository contains tests or a changelog. The documentation is useful, while the missing verification and change-history artifacts are a modest transparency gap.

Repo bus factorcaution

All 73 recent commits came from one contributor, giving a 100% top-contributor share. Although organization ownership provides some ability to hand off maintenance, the observed contributor concentration remains a continuity risk.

Repo popularitycaution

The repository has only 3 stars and 4 forks, indicating limited public adoption. Popularity is supporting evidence rather than a verdict, so this is a minor concern rather than a major health risk.

Security policycaution

The repository has no security policy. This weakens vulnerability-reporting transparency, though CodeQL scanning provides partial compensating security practice.

Token permissionscaution

The CodeQL workflow lacks top-level permissions and does not declare read-only permissions at the top level; it has job-level permissions only and no top-level write access. This is a workflow-hardening gap, but no dangerous workflow behavior was detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Küstenschmiede GmbH Software & Design

Direct Dependencies

DependencyLast ReleaseScore
con4gis/groups
Version ^2.10
con4gis/projects
Version ^5.0.36
con4gis/documents
Version ^1.6.4
contao/core-bundle
Version ^4.13 || ^5.3
contao/calendar-bundle
Version ^4.13 || ^5.3

Weekly Downloads

Info

Last Published
14 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform