Package Health

opencontent/ocbootstrap-ls

This release appears usable and actively maintained: it has a long release history, a current stable version, a recent release, an unarchived organization-owned repository, recent commits from two contributors, and no install-time scripts or registry deprecation. However, transparency and maintenance confidence are reduced by the absence of tests and a security policy, very low repository adoption indicators, and the linked repository neither matching the package name nor mentioning the package in its README; verify the repository relationship and fit before adopting it for a critical dependency.

Latest 2.1.6PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

A README and changelog are present, but neither the artifact nor repository contains tests; for a substantial 966-file legacy design package, the absence of visible tests is a genuine maintenance and regression-risk gap.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, so the linkage is not independently corroborated and may indicate that the package is using a repository intended for something else.

Repo popularitycaution

The repository has zero stars, two forks, and one watcher, so external adoption and review appear limited; this is supporting caution rather than evidence of abandonment because recent activity is present.

Repo toolingcaution

Composer is used as a build tool, providing expected package tooling, but no security scanning tools are configured, leaving security hygiene less transparent.

Security policycaution

No repository security policy was found, reducing guidance and transparency for reporting vulnerabilities in a package that may be deployed in legacy web applications.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

OpenContent

Direct Dependencies

DependencyLast ReleaseScore
ezsystems/ezpublish-legacy-installer
Version *

Weekly Downloads

Info

Last Published
17 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform