Package Health

leadingsystems/contao-cajax

The stable release has clear README and release notes, and organizational backing provides some continuity. Its proprietary licensing and four months without recorded commits leave important adoption and maintenance concerns.

Latest v3.0.2PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensedanger

The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. This creates a material transparency and dependency-use concern.

Release historycaution

The package has existed for over eight years but has only nine releases, with one release in the last 12 months and a typical interval of about nine months. That indicates a slow maintenance cadence, though the package is not abandoned outright.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. Although a recent release exists, the lack of observed ongoing activity raises maintenance risk.

Repo popularitycaution

The repository has no stars or forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of broad community review or adoption.

Repo toolingcaution

Composer is used as the build tool, but no security-scanning tools are reported. The missing scanner is a hygiene limitation rather than evidence that the release is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
contao/core-bundle
Version ^4.13 || ^5.0
—
—
leadingsystems/contao-helpers
Version ^3.0.0
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform