Package Health

magentixbr/magento2-cms-author

The package is clearly scoped, documented, and easy to identify in its matching source tree. Its long silence and license mismatch make a current Magento dependency a risky choice.

Latest 1.0.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

This is a single-release package first and last released on August 30, 2021, with no releases in the past year; the lack of subsequent maintenance is a substantial abandonment concern.

Repo commit activitydanger

The repository had no commits and no active maintainers in the past three months, consistent with the last push in August 2021 and indicating that maintenance has stopped.

Licensecaution

A license file is present, but the manifest declares OSL-3.0 and AFL-3.0 while the artifact license file was detected as BSD-2-Clause; that mismatch creates licensing uncertainty.

Repo popularitycaution

The repository has zero stars and forks and only two watchers, providing little evidence of external adoption or community support; this reinforces, but does not independently establish, the maintenance concern.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a transparency gap for a package integrated into Magento sites.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
magento/framework
Version >=102.0.0
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform