Package Health

imagewize/simple-cookie-consent

Unfit to use: Packagist marks this package abandoned and points to a replacement, so new projects should depend on imagewize/warder-cookie-consent instead. The replacement repository is active and the release is well documented, but those strengths do not offset the package-level deprecation.

Latest v2.2.2PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names imagewize/warder-cookie-consent as its replacement. Package-level deprecation is a severe dependency-maintenance risk even though the assessed release itself is current.

Repo package mentioncaution

The repository name does not match this package and its README does not mention the package, so the linkage is not transparent. This is especially relevant because the registry identifies this package as replaced by that repository’s package.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a security-process gap, though the active repository and clean workflow analysis provide some compensating evidence.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response guidance undocumented. This is a transparency gap for a package that handles website consent behavior.

Token permissionscaution

All three workflows lack top-level token-permission declarations, so their GitHub Actions permissions are not explicitly minimized. No workflow requests top-level write access, which limits the practical concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jasper Frumau

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ^2.0

Weekly Downloads

Info

Last Published
1 day ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform