Package Health

mautic/plugin-tagmanager

This is a mature, stable, non-deprecated Mautic plugin with a substantial release history, a current release, low runtime dependency complexity, tests, and organizational backing. The linked repository is explicitly a read-only mirror managed centrally in Mautic Core, which explains its lack of recent local commits and issue activity, but the release remains reasonably maintainable through the parent project. Adoption is tempered by the absence of any detected license file or declaration, no security policy or scanning tooling, and a pull_request_target workflow without explicit top-level token permissions; these are transparency and repository-hygiene concerns rather than evidence that the package is unfit to use.

Latest 7.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Dangerous workflowscaution

The repository has one pull_request_target workflow, which carries elevated workflow trust concerns even though no untrusted checkout or script injection was detected. Its presence warrants caution during contribution and automation review.

Licensecaution

Neither a declared license nor a license file was detected. This is a genuine legal and transparency gap for a dependency, although it does not by itself indicate abandonment.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools were detected. The build setup is appropriate, while the lack of scanning modestly weakens repository hygiene.

Security policycaution

No security policy was detected. That reduces transparency about vulnerability reporting and response, though the package's organizational ownership provides some context for where security handling may occur.

Token permissionscaution

The only workflow lacks top-level token permissions, and no read-only or explicit permissions declaration was detected. This leaves workflow authorization less transparent than preferred, although no top-level write permission was observed.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
mautic/core-lib
Version ^7.0

Weekly Downloads

Info

Last Published
20 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform