Package Health

qbus/subsite-generator

Its small footprint and lack of a security policy add transparency concerns, though organization backing and a stable release provide some reassurance. Treat 2.4.0 as legacy and pin it only with an ownership plan.

Latest 2.4.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was about 5 years ago, with no releases in the last 12 months. The package had a reasonable earlier cadence, but the prolonged halt materially raises abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers over the last 3 months, consistent with the release pause and indicating no current maintenance capacity.

Package scaffoldingcaution

The artifact has no README, tests, or changelog, and the repository also reports none. Missing tests and changelog are not expected in the published artifact, but the absent README modestly reduces consumer documentation for this extension.

Repo popularitycaution

The repository has 0 stars and 0 forks, with only 3 watchers. Popularity is supporting evidence rather than decisive, but these numbers provide little evidence of a broad user or contributor base.

Repo toolingcaution

The repository uses Composer for builds, appropriate for a Packagist PHP package. No security scanning tools are configured, but that is a modest hygiene gap compared with the maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Benjamin Franzke

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^10.4
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform