Package Health

helsingborg-stad/modularity-testimonials

This is a generally healthy release to depend on: it has a long release history since 2017, five releases in the last 12 months, a stable non-prerelease version, no registry deprecation, an active non-archived organization-backed repository, and current release activity. The main concerns are that repository commit activity shows no commits or active maintainers in the last three months, the artifact and repository lack README, tests, and changelog coverage, and the single release workflow lacks top-level token permissions and a security policy. These are meaningful transparency and maintenance-process gaps, but they are outweighed by the package's longevity, recent releases, repository backing, build and security tooling, and clean workflow-risk profile.

Latest 4.0.6PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a resilience concern in isolation. The concern is partly compensated by the linked repository being owned by the Helsingborg Stad organization.

Package file treecaution

The artifact contains a focused PHP module with Composer metadata and PHPUnit configuration, while the repository includes additional build and lock files. The structure is coherent, although the absence of tests in the tree limits verification evidence.

Package scaffoldingcaution

The artifact and repository lack a README, tests, and changelog; GitHub Releases provide some release communication, but the missing documentation and test evidence remain transparency and maintenance gaps.

Repo commit activitycaution

No commits and no active maintainers were observed during the last 3 months, which is a meaningful maintenance-risk signal. The recent release and merged pull request provide some compensation, but do not eliminate the recent commit-activity gap.

Repo popularitycaution

The repository has 1 star and 1 fork, so external adoption evidence is limited. Popularity is supporting evidence only and does not outweigh the stronger maintenance signals.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nikolas Ramstedt

Direct Dependencies

DependencyLast ReleaseScore
helsingborg-stad/wpservice
Version ^2.0
—
—
helsingborg-stad/wputilservice
Version ^0.3
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform