Package Health

greenpeace/planet4-gpch-plugin-tamaro

Healthy and reasonable to adopt, with a clear license, frequent recent releases, and an active organization-backed repository. The main concerns are that all recent commits come from one contributor and the repository does not clearly identify or mention this package; no security policy is published.

Latest v1.0.27PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo bus factorcaution

One contributor made all 6 recent commits, creating a meaningful single-maintainer continuity risk. Organization backing partly compensates because maintenance can potentially be handed off.

Repo commit activitycaution

The repository recorded 6 commits in the last 3 months and 1 active maintainer, which demonstrates recent activity but limited visible maintenance capacity.

Repo package mentioncaution

The repository name does not exactly match the package name and its README does not mention the package, so it is not fully clear that the linked repository specifically backs this release.

Repo toolingcaution

Composer is used as a build tool, which supports reproducible project structure, but no security scanning tools are reported. The lack of scanning lowers assurance somewhat without outweighing the active release history.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented. This is a transparency gap, though it is not evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
12 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform