Package Health

jweiland/pforum

Version 7.0.0 appears to be a healthy, actively maintained release from a long-lived package with 22 releases since 2017, 12 releases in the last 12 months, a stable major version, an active non-archived organization-owned repository, and recent activity from two maintainers. The repository and package clearly correspond, the artifact is licensed and documented, dependencies are minimal, and the CI workflow shows no analyzed dangerous patterns. The main reservations are concentrated commit activity, no repository security policy or dedicated security scanning, and workflow token permissions that are not explicitly constrained; these are meaningful hygiene concerns but do not outweigh the strong release and maintenance evidence.

Latest 7.0.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

Two contributors were active, but one authored 6 of 7 commits, an 86% share. The organization-owned repository and continued second-contributor activity partly mitigate this concentration, but it remains a maintenance-continuity caution.

Repo popularitycaution

The repository has seven forks and three watchers but no stars. This is limited supporting visibility, though low popularity is not by itself a health failure for a specialized extension.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. For a maintained extension this is a genuine security-process gap, though it is not evidence of malicious behavior.

Security policycaution

No repository security policy was found, which reduces transparency about vulnerability reporting and response procedures.

Token permissionscaution

The sole workflow has no top-level token permissions declaration. Although no top-level write permissions were detected, the absence of an explicit restrictive policy is a workflow-hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Stefan Froemken
Hoja Mustaffa Abdul Latheef

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^13.4

Weekly Downloads

Info

Last Published
15 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform