Package Health

lloc/multisite-language-switcher

This is a healthy, actively maintained release with a six-year history, 48 releases, six releases in the last 12 months, a stable non-prerelease version, and no registry deprecation. The linked repository is active and unarchived, has tests, changelog, build tooling, Dependabot scanning, and recent activity from four contributors, although commit ownership is concentrated in one contributor and there is no security policy. Install-time Composer lifecycle scripts and several workflows with write permissions warrant review in a deployment-sensitive environment, but the package's strong release cadence, repository transparency, licensing, and current maintenance substantially outweigh these concerns.

Latest 3.0.3PackagistPackagist

87%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

The package defines post-install-cmd and post-update-cmd scripts, which add install-time execution and deserve review before adoption. Their presence is a supply-chain and reproducibility consideration, but not by itself evidence of abandonment.

Maintainerscaution

Only one account has registry publish access, which creates publishing continuity risk. However, registry access reflects authorization rather than actual maintenance, and the repository shows four active contributors recently.

Project backingcaution

The repository owner is an individual user rather than an organization, so the concentrated contributor activity and single registry maintainer are not offset by explicit organizational backing.

Repo bus factorcaution

Commit activity is concentrated in the top contributor at 83.3% (30 of 36 commits), creating a genuine continuity concern. This is partly mitigated by three additional contributors remaining active during the same period.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. The presence of Dependabot provides some compensation but does not replace a policy.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dennis Ploetner

Direct Dependencies

DependencyLast ReleaseScore
php-di/php-di
Version ^6.4
—
—
composer/installers
Version ~2.3.0
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform