Package Health

seiger/sseo

This release appears reasonably safe to depend on from a maintenance and transparency perspective: it has a stable release line, 21 releases over about 3 years, 10 releases in the last 12 months, an active non-archived repository, and 12 commits from 3 active contributors in the last 3 months. The main concerns are install-time lifecycle scripts, no repository security policy or security scanning, and a workflow with top-level write permissions; the package and repository also lack tests and a changelog according to the collected scaffolding signal. These are meaningful hygiene and operational risks, but they do not outweigh the evidence of current maintenance and a repository that matches and documents the package.

Latest v1.3.3PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

The package declares post-autoload-dump, post-install-cmd, and post-update-cmd scripts, which execute during Composer operations and increase installation-time behavior and review risk.

Maintainerscaution

Only one account has registry publish access. This is a modest publishing bus-factor concern, but registry access is administrative evidence and is partly offset by the repository's three active contributors.

Package scaffoldingcaution

The collected scaffolding signal reports no README, tests, or changelog in the package or repository, although GitHub Releases are used. The lack of tests and changelog reduces transparency and verification coverage.

Project backingcaution

The repository is owned by a personal user account rather than an organization. This provides less institutional continuity than organization backing, although recent activity shows the project is currently maintained.

Repo bus factorcaution

The top contributor accounts for about 58% of recent commits, but two additional contributors account for the remaining 42%. The concentration warrants monitoring but is not severe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Serhii Korneliuk

Direct Dependencies

DependencyLast ReleaseScore
evolution-cms/evolution
Version ^3.5

Weekly Downloads

Info

Last Published
19 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform