Package Health

dcsg/mailchimp-api-connector-bundle

The bundle is small, clearly licensed, and has a focused dependency profile with no install-time scripts. It lacks security scanning and a security policy, leaving little evidence of ongoing oversight.

Latest v2.0.1PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has only three releases, all concentrated around March 2014, with no releases in the last 12 months and a package age of about 12.5 years. This is strong evidence of abandonment for a maintained integration package.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months. Combined with the last push in 2014, this indicates sustained abandonment.

Project backingcaution

The repository is owned by a personal user account rather than an organization. That does not prove the project is unsafe, but it provides no organizational maintenance backing to offset the inactivity.

Repo issue activitycaution

There were no recent issues or pull requests, and none are currently open. This is consistent with an inactive project, though it provides less evidence than the release and commit history.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools are configured. The build setup is appropriate, while the missing security tooling is a modest transparency and oversight gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Gomes

Direct Dependencies

DependencyLast ReleaseScore
dcsg/mailchimp-api-connector
Version ~2.2

Weekly Downloads

Info

Last Published
12 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform