Package Health

distantnative/kirby-csv-field

The package is small and focused, with a clear MIT license and release notes for this version. Maintenance has been quiet for over a year, and its workflow uses broad permissions and unpinned actions.

Latest 1.1.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The registry namespace and repository are owned by the same individual account, so ownership is consistent, but there is no organizational backing shown to compensate for the thin maintainer base.

Release historycaution

The package has five releases since May 2024, but none in the last 12 months; the latest release was over a year ago. This indicates a meaningful maintenance slowdown, though the release history is established rather than abandoned outright.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This raises maintenance and abandonment risk for a dependency.

Repo toolingcaution

The project uses Composer, which matches its PHP package ecosystem. No security scanning tooling was detected, a modest transparency and maintenance gap, but not a severe risk on its own.

Workflow auditcaution

The single workflow was fully analyzed and has no detected untrusted checkout or script-injection paths, but it grants top-level write permissions and all five action references are unpinned. These are workflow hygiene and supply-chain weaknesses without a detected dangerous sink.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nico Hoffmann

Direct Dependencies

DependencyLast ReleaseScore
getkirby/cms
Version ^4.0 || ^5.0
—
—
getkirby/composer-installer
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform