Package Health

ecodev/newsletter

The release has a README, tests, and detailed notes for its database and encryption migration. Its source and registry metadata otherwise provide no credible basis for ongoing maintenance, so pinning it would leave substantial upgrade and support risk.

Latest 4.0.0PackagistPackagist

12%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Are you affected? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement package supplied. Package-level deprecation is a severe adoption warning rather than a release-specific notice.

Release historydanger

The package has 21 releases and a historical median interval of about 33 days, but it has had no releases in the last 12 months and was last released in February 2019. The earlier cadence does not compensate for the prolonged halt.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months. Combined with the archived state, this shows maintenance has stopped rather than merely slowed.

Repository archiveddanger

The linked Ecodev/newsletter repository is archived, which indicates the source project is no longer maintained. Its last push was in April 2019, about seven years ago.

Vulnerabilities

TitleVersionsSeverity
CVE-2021-38302
ecodev/newsletter is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 4.0.0.
0.0.0 - 4.0.0
Low

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^7.6 || ^8.7
—
—
typo3/cms-fluid
Version ^7.6 || ^8.7
—
—
typo3/cms-backend
Version ^7.6 || ^8.7
—
—
typo3/cms-extbase
Version ^7.6 || ^8.7
—
—
typo3/cms-scheduler
Version ^7.6 || ^8.7
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform