Package Health

devgroup/dotplant

Risky to adopt: the package and its source repository have seen no release or commit activity since April 2017. It is clearly backed by the matching organization and is an understandable Composer meta-package, but its long abandonment gap makes it a liability for new projects.

Latest 1.0.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Release historydanger

Only five releases exist, with no release in the last 12 months and the latest release published in April 2017. This is a major maintenance concern for a package that aggregates core application dependencies.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months, consistent with its last push in April 2017. This strongly indicates abandonment rather than merely a slow development cycle.

Dependency profilecaution

This meta-package declares 17 runtime dependencies, including the CMS core and multiple project modules, so stale maintenance can affect a substantial dependency surface. The broad list is expected for a meta-package but increases the impact of its inactivity.

Repo toolingcaution

Composer is used for the build and dependency workflow, which is appropriate for this package. No repository security scanning is configured, leaving a transparency and maintenance gap, although the repository has no active workflow surface.

Security policycaution

The repository has no security policy. This is a transparency gap, especially for a package aggregating many runtime dependencies, though it is secondary to the much stronger evidence of long-term inactivity.

Vulnerabilities

TitleVersionsSeverity
CVE-2020-25750
devgroup/dotplant is vulnerable to Improper Restriction of XML External Entity Reference in versions 0.0.0 - 2020-09-14.
0.0.0 - 2020-09-14
High

Package versions

Maintainers

Alexander Kozhevnikov

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version ~2.0.6
—
—
symfony/process
Version ~3.0.0
—
—
dotplant/monster
Version dev-master
—
—
knplabs/packagist-api
Version ~1.3
—
—
devgroup/yii2-polyglot
Version ~1.0
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform