Package Health

hofff/contao-navigation-article

This is a mature, actively released Contao extension with over 11 years of package history, a stable 3.0.0 release, an unarchived repository, current repository activity through pull requests, and clear Composer and Dependabot tooling. The main concerns are that no commits were recorded in the last 3 months, the artifact and repository contain no tests or changelog, and the sole workflow does not declare top-level token permissions; these reduce transparency and maintenance confidence but are not, on the provided evidence, severe enough to make the package unfit to depend on.

Latest 3.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package has 11 runtime dependencies, including Contao, Symfony, Doctrine, and related extensions. This is a meaningful integration surface and therefore increases upgrade coupling, but the dependencies are consistent with the bundle's stated functionality.

Package scaffoldingcaution

A concise README documents configuration and usage, but neither the artifact nor repository has tests or a changelog. For a small integration bundle this is a genuine transparency and regression-coverage gap.

Repo commit activitycaution

No commits and no active maintainers were recorded in the last 3 months, which is a maintenance concern. However, the recent release, repository push, and pull-request activity provide partial compensating evidence.

Repo popularitycaution

The repository has 0 stars, 2 forks, and 1 watcher. This is weak supporting popularity evidence, but popularity is not decisive for a specialized package.

Security policycaution

No repository security policy was found. This is a transparency gap, though it is less significant for a small application bundle than for security-sensitive infrastructure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Oliver Hoff
David Molineus
Nicky Hoff

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ^3.10 || ^4.0
—
—
symfony/config
Version ^6.4 || ^7.4
—
—
contao/core-bundle
Version ^5.3
—
—
symfony/http-kernel
Version ^6.4 || ^7.4
—
—
hofff/contao-content
Version ^4.1.2
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform