Package Health

sioweb/contao-element-group

It has a stable 1.0.1 version, no install-time scripts, and a declared LGPL-3.0-or-later license. The single-maintainer project has no README or security policy, reducing transparency and making long-term support less clear.

Latest v1.0.1PackagistPackagist

56%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Maintainerscaution

Only one registry maintainer is listed, leaving a thin publishing base. The linked repository is user-owned rather than organization-backed, so there is no provided evidence that a broader team compensates for this.

Package scaffoldingcaution

The package contains no README, tests, or changelog, and the repository also reports none. Missing tests and changelog are acceptable for a published artifact, but the missing README reduces consumer transparency for this library-style extension.

Release historycaution

The package has had only two releases, both published in January 2025, with no releases in the following 20 months. That weakens evidence of ongoing maintenance, although a small stable extension may not need frequent releases.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months, consistent with roughly 20 months without a release. This is a meaningful abandonment risk for future compatibility fixes.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tooling is reported. This is a modest transparency gap rather than evidence of an unsafe release.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sascha Weidner

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform