Package Health

mteu/typo3-monitoring

Clear documentation, a license, and release notes support adoption. The install-time script and absent repository security scanning warrant extra operational review.

Latest 1.0.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

A post-install command runs during installation, adding execution-time supply-chain and deployment complexity compared with a package without lifecycle scripts.

Repo bus factorcaution

All 52 recent commits came from one contributor, so maintenance depends heavily on a single person despite the strong recent activity.

Repo toolingcaution

Composer is used for builds, but no security scanning tools were detected. This is a transparency and defense-in-depth gap, not evidence that the release is unsafe.

Workflow auditcaution

All four workflows use read-only permissions and all 25 analyzed action references are pinned, but the release workflow has four high-confidence template-injection findings. With no untrusted checkout or script-injection trigger reported, this remains a workflow hygiene concern rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Martin Adler

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
psr/clock
Version ^1.0
—
—
symfony/mime
Version ^7.4
—
—
doctrine/dbal
Version ^4.4
—
—
symfony/mailer
Version ^7.4
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform