Package Health

digital-marketing-framework/typo3-core

Usable with caveats: the package is actively released, stable, tested, and backed by an organization, but recent repository activity is very thin and all recent commits came from one contributor. It also lacks a README and a security policy, which reduces transparency for a library dependency.

Latest 4.2.0PackagistPackagist

73%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Lifecycle scriptscaution

The package defines a post-autoload-dump lifecycle script, which adds install-time execution and therefore some supply-chain exposure. No evidence here shows that the script is unsafe, so this is a limited concern rather than a severe risk.

Package scaffoldingcaution

The artifact and repository include tests, and this exact version has GitHub release notes describing a change. The missing package README is a transparency gap for a library consumers must integrate, while the absent changelog is compensated by the release notes.

Repo bus factorcaution

All recent repository commits came from one contributor, giving a 100% top-contributor share. Organization backing provides some handoff potential, but no second active contributor is shown in this period, so the concentration remains a concern.

Repo commit activitycaution

Only one commit was recorded in the last 3 months, with one active maintainer. Despite the recent release cadence, this thin observed development activity creates a real risk that maintenance capacity is limited.

Security policycaution

No repository security policy was found. For a framework component, the absence of documented vulnerability-reporting guidance reduces security transparency, although scanning tools provide partial operational compensation.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mediatis AG

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^12.4 || ^13.4.9 || ^14.3
typo3/cms-install
Version ^12.4 || ^13.4 || ^14.3
digital-marketing-framework/core
Version ^3.17

Weekly Downloads

Info

Last Published
5 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform