Package Health

dmk/t3rest

Maintenance rests on one active contributor, and the repository has no security policy. The artifact declares GPL-2.0-or-later while its detected license file is MIT, so licensing should be clarified before adoption.

Latest v13.0.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

33

Health Score Breakdown

Workflow auditdanger

Both workflows were analyzed without audit gaps, but all 11 action references are unpinned and the release workflow has a high-confidence template-injection finding that may expand attacker-controlled input into code. No untrusted checkout or script-injection trigger was detected, limiting the severity.

Licensecaution

The manifest declares GPL-2.0-or-later, but the detected artifact license is MIT; although license files are present, this mismatch requires clarification before use.

Lifecycle scriptscaution

A post-autoload-dump script runs during installation. This is a supply-chain-sensitive behavior, but it is a normal Composer lifecycle hook and is not severe on its own.

Repo bus factorcaution

All 4 recent commits came from one contributor, creating a meaningful continuity risk even though the repository owner is an organization.

Repo popularitycaution

The repository has only 1 star and 1 fork, indicating limited adoption evidence. Popularity is supporting evidence rather than a decisive health measure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

René Nitzsche
Michael Wagner

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^12.4 || ^13.4
—
—
digedag/rn-base
Version ~1.20.0
—
—

Weekly Downloads

Info

Last Published
3 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform