Package Health

digedag/dflsync

The repository remains identifiable and the package includes a useful README, but its maintenance trail is thin. Unpinned workflow actions and no security policy add smaller transparency and supply-chain concerns.

Latest v0.2.3PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

60

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has only 3 releases, with none in the last 12 months and the latest released in April 2021. This is a substantial maintenance concern despite the repository receiving a later push.

Repo commit activitycaution

The repository had no commits and no active maintainers in the measured 3-month period. A last push in July 2024 shows it is not archived, but does not demonstrate current maintenance.

Repo toolingcaution

Composer is used for the build, which is appropriate for this package, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy, leaving no documented route for reporting vulnerabilities. This is a transparency gap for a package that integrates external feed data.

Version stabilitycaution

The current v0.2.3 release is not marked as a prerelease, but the 0.x major version signals a less mature compatibility commitment. Its non-prerelease status partly offsets that concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

René Nitzsche

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^8.7
—
—
digedag/rn-base
Version ^1.13.0
—
—
digedag/cfc-league
Version ^1.6.0
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform