Package Health

realloc/multisite-language-switcher

This release has strong evidence of active development and reasonable project hygiene: it has a long release history, a stable version, current repository activity, tests, a changelog, licensing, security scanning, and a repository that matches the package. However, the Packagist listing is explicitly marked abandoned and names `lloc/multisite-language-switcher` as its replacement, which is a severe dependency-health concern even though the linked repository is active and the latest release is recent. The repository also has a concentrated commit profile and incomplete workflow/security-policy hardening. Prefer the replacement package rather than adding this abandoned package directly.

Latest 3.0.3PackagistPackagist

30%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Registry deprecationdanger

Packagist marks this package as abandoned and provides `lloc/multisite-language-switcher` as a replacement. Active repository and recent release activity mitigate abandonment concerns about the underlying project, but they do not remove the risk of depending on the deprecated package identity.

Lifecycle scriptscaution

The package declares `post-install-cmd` and `post-update-cmd` lifecycle scripts. These add install-time execution surface, although the available evidence does not establish that the scripts are unsafe or unusually broad.

Project backingcaution

The repository owner is a user account rather than an organization, so there is no organizational handoff capacity shown by this signal. The four active contributors provide some practical compensation, but recent commits remain concentrated.

Repo bus factorcaution

One contributor made 30 of 36 recent commits, or about 83%, while three others contributed the remainder. The additional active contributors provide some coverage, but the high concentration creates a meaningful continuity risk for a user-owned project.

Security policycaution

No security policy was found in the repository. This is a transparency gap, though it is partly offset by active maintenance and Dependabot scanning.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dennis Ploetner

Direct Dependencies

DependencyLast ReleaseScore
php-di/php-di
Version ^6.4
—
—
composer/installers
Version ~2.3.0
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform