Package Health

flute-cms/cms

This release appears generally suitable to depend on: it is a licensed, non-deprecated stable release from a repository that is actively published, has substantial source and artifact documentation, repository tests, changelog and release support, and clear organization backing. The main concerns are that only two commits were recorded in the last three months, all by one contributor, the project has no security scanning or security policy, and several workflows use broad or unspecified token permissions, including a workflow with pull-request-target and untrusted checkout behavior. The package also has a large runtime dependency surface, increasing maintenance complexity, but its long release history and recent release activity materially offset that concern.

Latest v1.0.7PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull-request-target with an untrusted checkout, creating a meaningful CI supply-chain exposure even though no script injection was detected in the analyzed workflows.

Dependency profilecaution

The package declares 61 runtime dependencies, including framework, database, payment, authentication, and asset-processing components; this is a substantial dependency surface that increases update and compatibility complexity.

Repo bus factorcaution

All two recent commits came from one contributor, producing a 100% top-contributor share. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown in this period.

Repo commit activitycaution

Only two commits were recorded in the last three months, with one active maintainer. This is materially slower than the release history suggests and warrants caution about current maintenance capacity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The build setup is established, while security-process coverage is incomplete.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Flames

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1 || ^2.0 || ^3.0
—
—
cycle/orm
Version ^2.8.0
—
—
ramsey/uuid
Version ^4.7
—
—
tracy/tracy
Version ^2.10
—
—
league/glide
Version ^2.3
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform