Package Health

dreibein/contao-jobposting-bundle

A stable major release, clear README, declared LGPL license, and no install-time scripts support adoption. The small user base and six unresolved issues reduce confidence in ongoing support. Pin this version and plan a migration path.

Latest 1.0.15PackagistPackagist

44%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the last push in November 2022. This is strong evidence that ongoing maintenance has stopped.

Release historycaution

The package has 16 releases since September 2021, but none in the 12 months before collection; its latest release was in November 2022, roughly 3 years and 10 months ago. This indicates a long-standing maintenance gap.

Repo issue activitycaution

Six issues remain open, with no new or closed issues and no pull-request activity in the last month. Combined with the inactive commits, this weakens confidence that support problems will be addressed.

Repo popularitycaution

The repository has 1 star, 0 forks, and 2 watchers, indicating a very small visible user base. Popularity is only supporting evidence, but it provides little reassurance when maintenance is also inactive.

Repo toolingcaution

The project uses Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Thomas Dirscherl

Direct Dependencies

DependencyLast ReleaseScore
contao/conflicts
Version @dev
contao/core-bundle
Version ^4.9

Weekly Downloads

Info

Last Published
3 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform