Package Health

r3h6/opentelemetry-auto-typo3

Tests and a usable README are present, and the repository is not archived. Only two releases exist over 596 days, recent commits are absent, and both workflow actions are unpinned.

Latest 0.1.1PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has only 2 releases across 596 days, with 1 release in the last 12 months and a median interval of about 419 days. This indicates a sparse maintenance cadence, though the latest release is recent.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months. Although the repository was recently pushed for the release, the measured lack of ongoing activity raises abandonment risk.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tool was detected. This is a modest repository-hygiene gap rather than evidence that the package is unsafe to depend on.

Security policycaution

The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, but it is not by itself evidence of abandonment.

Version stabilitycaution

Version 0.1.1 is not a stable major release, so the public API may still change. It is not marked as a prerelease, which partly offsets the concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^12.4 || ^13.4
open-telemetry/api
Version ^1.0
open-telemetry/sdk
Version ^1.0
php-http/guzzle7-adapter
Version *
open-telemetry/exporter-otlp
Version ^1.0

Weekly Downloads

Info

Last Published
5 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform