Package Health

mpl/matomo

Matomo is the leading Free/Libre open analytics platform

Latest 5.14.1PackagistPackagist

62%

Total Score

caution

Usable with caveats: frequent registry releases contrast with a repository showing no recent commits.

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Frequent registry releases provide some compensation, but this source-repository inactivity remains a maintenance concern.

Repo toolingcaution

The repository uses Composer, but no security scanning tools were detected. Build tooling is present, while the missing scanning coverage is a modest transparency gap.

Security policycaution

No security policy was found in the linked repository. For a full analytics application handling potentially sensitive data, this leaves vulnerability-reporting expectations unclear.

Workflow auditcaution

Both workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, weakening build reproducibility and supply-chain controls.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

The Matomo Team

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ~1.0
—
—
twig/twig
Version >=3.11.3 <3.12
—
—
lox/xhprof
Version dev-master
—
—
matomo/ini
Version ~3.0
—
—
matomo/cache
Version ~3.0
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform