Package Health

konradmichalik/typo3-routing

This is a healthy, actively developed release with strong recent maintenance evidence: 11 releases in 72 days, 218 commits in the last 3 months, recent repository activity, extensive source documentation, repository tests, security scanning, and a security policy. The main concerns are that nearly all recent commits come from one contributor, the package uses a post-install lifecycle script, and GitHub Actions workflows do not declare top-level permissions; these warrant review but do not outweigh the package’s active development and repository hygiene. Its young age and low popularity limit maturity evidence, so dependency adoption should still include normal upgrade and maintainer-continuity monitoring.

Latest 1.4.0PackagistPackagist

80%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Lifecycle scriptscaution

A post-install-cmd script introduces install-time behavior that consumers should inspect, although the signal does not establish that the script is unsafe or unusually complex.

Maintainerscaution

Only one registry account has publish access. Because the repository is user-owned rather than organization-owned, this represents some publishing continuity risk, although repository activity shows an active maintainer.

Project backingcaution

The linked repository is owned by an individual user, not an organization, so there is no organizational backing to compensate for the concentrated contributor and single registry publisher base.

Repo bus factorcaution

Two contributors were active, but the top contributor made 217 of 218 commits, creating a highly concentrated maintenance dependency. The second contributor’s activity is too small to materially offset that concentration for a user-owned project.

Repo popularitycaution

The repository has only 6 stars, 1 fork, and 0 watchers. This is limited supporting evidence of community adoption, but popularity is not decisive for a small, actively maintained package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Konrad Michalik

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^1.1 || ^2.0
—
—
typo3/cms-core
Version ^13.4 || ^14.0
—
—
symfony/console
Version ^7.0 || ^8.0
—
—
symfony/routing
Version ^7.0 || ^8.0
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—

Weekly Downloads

Info

Last Published
22 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform