Package Health

copperis/dropdownimagefield

The package has a small dependency surface and a recent release with notes, but the project shows no commits in the last three months. Its license files disagree, and the lone workflow uses an unpinned action.

Latest 2.0.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

A license file is present, but the manifest declares MIT while the artifact license is recognized as BSD-3-Clause. The mismatch reduces licensing transparency despite the repository also containing a license file.

Release historycaution

The package has only two releases across nearly ten years, with a median interval of about nine years; one release in the last year provides some evidence of renewed activity but not a dependable cadence.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the recent release shows the project was updated within the broader period.

Repo popularitycaution

The repository has four stars and seven forks, indicating a small user and contributor footprint. Low popularity is supporting context rather than a health verdict.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a hygiene gap, not evidence of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
silverstripe/framework
Version ^6

Weekly Downloads

Info

Last Published
9 months ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform