Package Health

labor-digital/typo3-better-api-composer-plugin

The package includes a README, changelog, matching source repository, and a clear Apache-2.0 license. Its repository has not been updated since May 2022, and all four workflow actions are unpinned, making this old release a maintenance liability.

Latest 4.1.0PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest registry release was published on May 6, 2022, with no releases in the last 12 months. More than four years without a release is strong evidence of stalled maintenance.

Repo issue activitycaution

The repository has no open issues or pull requests and recorded no issue or pull-request activity in the last month. This is consistent with a dormant project, although it does not by itself prove abandonment.

Repository archivedcaution

The linked repository is not archived, which avoids an immediate abandonment indicator. However, its last push was on May 6, 2022, consistent with the stale release history.

Security policycaution

The linked repository has no security policy. For a small, old Composer plugin this is a transparency gap, though it is less significant than the lack of recent releases.

Workflow auditcaution

Both workflows were analyzed successfully and have no untrusted checkouts, script injection, dangerous triggers, or audit findings. However, all four action references are unpinned, leaving the build exposed to dependency changes over time.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

LABOR.digital
Martin Neundorfer

Direct Dependencies

DependencyLast ReleaseScore
neunerlei/path-util
Version ^2.4
—
—
neunerlei/filesystem
Version ^5.2
—
—
typo3/class-alias-loader
Version ^1.1.1
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform