Package Health

heimrichhannot/contao-tinymce-bundle

This release is generally usable, with a six-year history, 16 releases, six releases in the last 12 months, a recent latest release, an unarchived repository, an organization-backed project, and clear package/repository alignment. Its main concerns are that repository commit activity shows no commits and no active maintainers in the last 3 months, the repository has very little visible adoption, the artifact and repository contain no tests, and the repository lacks a security policy and explicit workflow token permissions. These are meaningful maintenance and transparency gaps, but they are partly offset by the recent release cadence, changelog, CI workflow, clean workflow-risk profile, and absence of install-time scripts.

Latest 0.4.5PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

A README and changelog are present, and the repository has a changelog and GitHub Releases, but neither the package nor repository contains tests. The documentation is adequate for a small bundle, while the missing tests leave a maintenance-quality gap.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months, which is a concrete short-term maintenance concern. The recent release history and repository push provide partial compensation, so this is caution rather than danger.

Repo popularitycaution

The repository has 1 star, 0 forks, and 3 watchers. Popularity is only supporting evidence, but these very low figures provide little independent evidence of broad community adoption.

Repo toolingcaution

Composer build tooling is present and the repository includes CI-related configuration, but no security scanning tools are reported. The tooling baseline is reasonable for the package, with a security-hygiene gap.

Security policycaution

No repository security policy is present. For a small package this is not independently disqualifying, but it reduces transparency around vulnerability reporting and maintenance practices.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/config
Version ^5.4 || ^6.0 || ^7.0
—
—
contao/core-bundle
Version ^4.13 || ^5.0
—
—
symfony/http-kernel
Version ^5.4 || ^6.0 || ^7.0
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform