Package Health

gonicus/gosa2-core

This release has solid transparency and packaging fundamentals: it is explicitly GPL-2.0-or-later licensed, includes license files, a changelog, a substantial repository tree, Composer build tooling, and no install-time lifecycle scripts. The linked repository is organization-owned, not archived, and was pushed recently, with some pull requests merged. However, the package registry history is extremely thin—this is the only release and it is only 1 day old—and recorded commit activity shows zero commits and zero active maintainers over the last 3 months, leaving maintenance maturity difficult to establish. The repository does not mention this package and its name does not match, which raises provenance ambiguity, while the absence of a security policy and incomplete workflow permission declarations are additional hygiene gaps. It is potentially usable, but should be adopted cautiously until its package-to-repository relationship and sustained maintenance are established.

Latest 2.8.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package has nine runtime dependencies, including PHP, Smarty, and several related GONICUS plugins, with no dev dependencies. This is a meaningful dependency surface but appears coherent with the package's plugin-oriented application role.

Package scaffoldingcaution

A README and changelog are present and the repository also has a changelog, although neither the artifact nor repository contains tests. The documentation compensates for the missing tests only partly, so the absence of tests remains a modest maturity gap.

Release historycaution

The package is only 1 day old with one release and no established release interval, so registry evidence cannot yet demonstrate sustained maintenance or release discipline.

Repo commit activitycaution

The repository records zero commits and zero active maintainers over the last 3 months. This conflicts with the recent push and merged pull requests, but the measured commit history still leaves sustained maintenance capacity unproven.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention gonicus/gosa2-core. Since the repository is not shown to reference this package, the package-to-source relationship is ambiguous and warrants verification before adoption.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Benjamin Zapiec

Direct Dependencies

DependencyLast ReleaseScore
smarty/smarty
Version ~4.3
—
—
gonicus/gosa2-plugin-ssh
Version dev-main
—
—
gonicus/gosa2-plugin-systems
Version dev-composer
—
—
gonicus/gosa2-plugin-departments
Version dev-main
—
—
gonicus/gosa2-plugin-ldapmanager
Version dev-composer
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
26 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform