Package Health

flowd/typo3-firewall

This release appears suitable for adoption with moderate caution: it is actively maintained, non-deprecated, backed by an organization-owned repository, and has substantial repository tests, documentation, CI, and recent commit activity. The main concerns are that version 0.9.0 is not yet a stable major release, activity is highly concentrated in one contributor, the repository lacks a security policy and security-scanning tooling, and one release workflow does not declare top-level token permissions. The unusually frequent release cadence also suggests an evolving project, though it provides evidence of active maintenance rather than abandonment.

Latest 0.9.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

Two contributors were active, but the leading contributor made about 95% of recent commits. The organization-owned repository provides some ability to hand off maintenance, but the observed activity remains highly concentrated.

Repo toolingcaution

The repository uses Composer and contains build and test configuration, supporting reproducible project maintenance. It reports no security-scanning tools, leaving a security-hygiene gap.

Security policycaution

The repository has no SECURITY.md or other detected security policy. For a package explicitly intended to protect web applications, this is a meaningful vulnerability-reporting and transparency gap.

Token permissionscaution

One of two workflows, release.yml, lacks top-level token permissions, while the other declares read-only permissions and neither declares top-level write access. The missing declaration weakens least-privilege assurance for the release workflow.

Version stabilitycaution

Version 0.9.0 is not a stable major release, so API and behavior compatibility may still change. It is not marked as a prerelease, which partially offsets the maturity concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sascha Egerer

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^12.4 || ^13.4 || ^14.0
flowd/phirewall
Version ^0.10.0
typo3/cms-backend
Version ^12.4 || ^13.4 || ^14.0

Weekly Downloads

Info

Last Published
18 days ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform