Package Health

openeuropa/oe_newsroom

This is a healthy, well-structured release with an established history, a current stable version, active repository maintenance, organizational backing, tests, documentation, changelog coverage, and a clear license. The repository is not archived or deprecated, has three active maintainers and 37 commits in the last 3 months, and its CI workflow shows no analyzed dangerous patterns. The main reservations are the roughly 324-day median release interval, absent repository security policy, and unspecified top-level GitHub Actions token permissions; these are meaningful hygiene gaps but are outweighed by current development activity and strong package transparency.

Latest 1.2.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

The package uses post-install-cmd and post-update-cmd scripts, which increase installation-time behavior and warrant review when depending on the release. No provided signal shows these scripts are malicious or unsafe, so this is a caution rather than a severe risk.

Release historycaution

The package has existed for about 4 years, with 6 releases and 2 releases in the last 12 months. The roughly 324-day median interval is slower than highly active projects, but the recent releases and repository activity indicate it is not abandoned.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a hygiene gap, while the separate workflow analysis found no dangerous workflow patterns.

Security policycaution

No SECURITY.md or equivalent security policy was detected, leaving vulnerability-reporting and response expectations less transparent. This is a maintenance and transparency gap, not evidence of an unsafe release by itself.

Token permissionscaution

The sole workflow does not declare top-level token permissions, so its effective GitHub Actions token scope is less explicit than preferred. No workflow with explicit write permissions was detected, limiting the severity of this gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
drupal/core
Version ^10 || ^11
—
—
drupal/multivalue_form_element
Version ^1.0@beta
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform