Package Health

dskzpt/personio

This release is usable but merits caution rather than being considered a highly mature dependency. It is a stable v2.0.0 release with an explicit GPL-2.0-or-later license, a complete 34-file package tree, no install-time lifecycle scripts, and a repository that matches and documents the package. The repository is organization-backed, active enough to have been pushed with the release, and has a recent merged pull request, but its longer-term maintenance evidence is thin: there have been only 9 releases since 2023, just 1 release in the last 12 months, and no commits or active maintainers in the preceding 3 months. The absence of tests, a changelog, security policy, and security scanning reduces transparency and assurance, although the package's small TYPO3 extension scope and lack of dangerous workflows limit the severity of those gaps.

Latest v2.0.0PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Package scaffoldingcaution

A substantive README and contributing document are present, but neither the artifact nor repository contains tests or a changelog. For a small extension this is a genuine transparency and maintenance gap, though GitHub Releases provide some compensating release communication.

Release historycaution

The package has existed for about 3 years 7 months with 9 releases, but only 1 release in the last 12 months indicates relatively limited recent release activity.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months. Although the release-time push and recent merged pull request provide some compensating evidence, the recent maintenance capacity remains thin.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. The missing scanning lowers assurance but is not by itself a severe dependency risk.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap for a package consumed in production.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sven Petersen

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^14.0
—
—

Weekly Downloads

Info

Last Published
25 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform