Package Health

jweiland/checkfaluploads

This is a healthy, established release with a track record since 2017, 25 releases, a stable current version, recent release activity, active repository work, clear licensing, a matching organization-owned repository, and comprehensive source documentation and tests. The main concerns are that all 23 commits in the last 3 months came from one contributor, the repository has no security policy or security-scanning tooling, and its workflow does not declare top-level token permissions. These are meaningful transparency and resilience gaps, but they are outweighed by active maintenance, recent merged pull requests, repository-backed tests, and the absence of deprecation or archival indicators.

Latest 6.0.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

Only one contributor made all 23 commits in the last 3 months, creating a real continuity risk. The organization-owned repository provides some potential for handoff, but no second active contributor is evidenced.

Repo popularitycaution

The repository has 0 stars, 1 fork, and 2 watchers, showing limited public adoption. Popularity is supporting evidence only, so this modest visibility is a caution rather than a decisive health problem.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured. The missing scanning is a security-hygiene gap, though it does not indicate abandonment on its own.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.

Token permissionscaution

The CI workflow lacks top-level token permissions, so its effective permissions are less explicit than recommended. No workflow with explicit top-level write permissions was found, limiting the severity of this gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Stefan Froemken
Hoja Mustaffa Abdul Latheef

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^13.4
typo3/cms-filelist
Version ^13.4

Weekly Downloads

Info

Last Published
15 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform