Package Health

cwp/starter-theme

The license, documentation, release notes, and organization backing provide useful transparency. Workflow references are all unpinned, and recent repository activity has not translated into releases or commits, so maintenance continuity is uncertain.

Latest 4.2.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Health Score Breakdown

Release historycaution

The package has 51 releases over about 9 years, but no registry release in the last 12 months; the latest release was in November 2024. This materially weakens confidence in ongoing maintenance.

Repo commit activitycaution

There were no commits and no active maintainers in the last 3 months. The repository's recent push timestamp is a compensating sign of activity, but the observed commit window still indicates uncertain maintenance continuity.

Repo issue activitycaution

The repository has 18 open issues and 12 open pull requests, but no new or closed issues and no merged pull requests in the last month. This suggests limited recent issue-management activity.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools were detected. The missing scanning layer is a modest transparency and hygiene concern, not evidence of abandonment by itself.

Workflow auditcaution

All 7 analyzed action references are unpinned, so workflow dependencies can change without a reviewed commit. The audit found no dangerous sinks, high-severity findings, or broad top-level write permissions, which keeps this at a hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
silverstripe/framework
Version ^5
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform