Package Health

friendsoftypo3/headless

The project has a long release history, recent publishing, organization backing, and repository activity. This release is a release candidate, while recent commits are limited to one contributor and all 13 workflow actions are unpinned.

Latest v5.0.0-rc2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

One contributor made all commits in the last three months, giving the recent activity a 100% concentration; organization backing provides some handoff capacity but does not remove the near-term concentration risk.

Repo commit activitycaution

Only one commit was recorded in the last three months, and only one maintainer was active; this is a meaningful sign of recently thin maintenance.

Security policycaution

The repository has no security policy, leaving vulnerability reporting guidance less transparent for consumers of this integration package.

Version stabilitycaution

v5.0.0-rc2 is a prerelease, so its API and behavior may still change; the recent prerelease share is only 10%, which partly limits the concern.

Workflow auditcaution

All three workflows were analyzed without high-confidence findings or untrusted checkout and script-injection patterns. However, all 13 action references are unpinned, which weakens build reproducibility; the absence of top-level permissions is not a concern by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tymoteusz Motylewski
Łukasz Uznański
TYPO3 PWA Initiative

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^14.0
—
—
typo3/cms-install
Version ^14.0
—
—

Weekly Downloads

Info

Last Published
22 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform