Package Health

lekoala/silverstripe-sparkpost

This is a generally usable and transparent package with a long history, stable releases, an active-looking recent registry release, a matching source repository, tests, a license, and no deprecation or dangerous workflow findings. However, the repository recorded zero commits and zero active maintainers in the last 3 months, while the single-user maintainer base, absent security policy, and undeclared workflow permissions leave meaningful maintenance and supply-chain hygiene gaps. The package is suitable to consider, but adoption should include monitoring for renewed repository activity and release quality.

Latest 3.1.7PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account, LeKoala, has publish access, creating concentration risk; the matching source repository provides some context but does not remove the single-publisher dependency.

Project backingcaution

The source repository is owned by the individual user LeKoala rather than an organization, so there is no organizational backing to offset the thin maintainer base.

Repo commit activitycaution

The repository shows zero commits and zero active maintainers over the last 3 months, a meaningful warning about current maintenance capacity despite the recent push and registry release.

Repo issue activitycaution

There are no open issues or pull requests, but there was also no issue or pull-request activity in the last month; this is neutral to mildly limiting rather than evidence of active maintenance.

Repo popularitycaution

The repository has 7 stars, 11 forks, and 2 watchers, indicating limited adoption; popularity is only supporting evidence, so this lowers confidence in maturity modestly but is not decisive.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

LeKoala

Direct Dependencies

DependencyLast ReleaseScore
pelago/emogrifier
Version ^7
—
—
composer/ca-bundle
Version *
—
—
silverstripe/framework
Version ^5
—
—
silverstripe/recipe-plugin
Version ^2
—
—
silverstripe/vendor-plugin
Version ^2
—
—

Weekly Downloads

Info

Last Published
23 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform