Package Health

seven.io/craft

The focused codebase is clearly tied to an organization and has a license, release notes, dependency automation, and a matching repository. Its limited adoption, absent recent commit activity, missing security policy, and workflow hygiene issue reduce confidence in long-term upkeep.

Latest v1.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

Only one release exists, published about 3 years ago, with no releases in the last 12 months. That is meaningful evidence of limited ongoing maintenance for a plugin dependency.

Repo commit activitycaution

There were no commits and no active maintainers in the last 3 months. Combined with the single-release history, this indicates weak evidence of active maintenance.

Repo issue activitycaution

There were no issues or pull requests opened or merged in the last month, while one issue and three pull requests remain open. This suggests limited recent project responsiveness.

Security policycaution

No security policy is present in the repository. That is a transparency gap for a plugin handling API credentials and messaging services.

Workflow auditcaution

The sole workflow uses a pull_request_target trigger, top-level write permissions, and an unpinned action; the high-confidence bot-conditions finding adds workflow hygiene concern. No untrusted checkout or script-injection sink was found, so this is not a severe risk on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

sms77 e.K.

Direct Dependencies

DependencyLast ReleaseScore
sms77/api
Version ^2.3.0
—
—
craftcms/cms
Version ^3.1.0
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform