Package Health

mautic/plugin-crm

This is a generally usable and actively released package with a long release history, a stable current version, organization backing, tests, and no registry deprecation or install-time scripts. However, the linked mirror repository shows no commits or active maintainers in the last 3 months, the package and repository have no detected license file or declaration, and the repository lacks security-scanning and security-policy coverage. The pull-request-target workflow without explicit top-level token permissions adds supply-chain hygiene concern, although the README explains that development is centrally managed in Mautic Core and the latest registry release is recent.

Latest 7.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

The repository has one pull_request_target workflow, which can be sensitive when handling untrusted pull requests. No untrusted checkout or script-injection pattern was detected, limiting the severity but leaving workflow risk to review.

Licensecaution

Neither a declared license nor a license file was detected in the artifact or repository, leaving the legal terms of dependency use unclear.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers over the last 3 months, which is a meaningful maintenance-visibility gap. The package's recent release history and README-documented central management partially compensate, but do not remove the concern for this mirror.

Repo popularitycaution

The repository has low popularity with 8 stars and 1 fork, but popularity is supporting evidence only and the organization backing, tests, and release cadence provide stronger context.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected, reducing automated supply-chain and code-security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
mautic/core-lib
Version ^7.0

Weekly Downloads

Info

Last Published
1 month ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform