Package Health

johannschopplich/kirby-serp-preview

The package is clearly documented, licensed, stable, and recently updated. Its small contributor base and workflow hygiene leave some maintenance and release-process risk.

Latest 1.4.2PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The repository is owned by an individual rather than an organization, so the single-contributor concentration is not visibly offset by organizational maintenance capacity.

Repo bus factorcaution

One contributor made all 27 recent commits, creating a meaningful continuity risk if that maintainer becomes unavailable.

Repo toolingcaution

The project uses a build tool, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy, so vulnerability reporting and handling expectations are not documented.

Workflow auditcaution

The only workflow gives top-level write permissions and all 3 action references are unpinned. The audit also reported a low-confidence cache-poisoning pattern; these are release-hygiene cautions, not evidence of a severe workflow compromise.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Johann Schopplich
Dennis Baum

Direct Dependencies

DependencyLast ReleaseScore
getkirby/composer-installer
Version ^1
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform