Package Health

ssch/t3-psr3-log-processor

The repository includes tests, a release note for this version, and Dependabot, but no commits in the last three months. The package's declared GPL-2.0+ license conflicts with the detected MIT license, and the linked repository does not name or mention this package.

Latest v1.0.0PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

The manifest declares GPL-2.0+, while the artifact license file is detected as MIT; the repository also has a license file, but the release's licensing is still inconsistent and needs clarification.

Release historycaution

This is the only release, published over three years ago, with no releases in the last 12 months. That leaves meaningful abandonment risk despite the repository remaining available.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is a concrete sign of limited recent maintenance for a package with only one release.

Repo package mentioncaution

The linked repository name does not match the package name and its README does not mention the package. That raises caution that the source repository may not clearly belong to this package.

Workflow auditcaution

All five workflows were analyzed with no untrusted checkouts, script injection, or audit findings. However, all 17 action references are unpinned, which is a supply-chain hygiene weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sebastian Schreiber

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^10.4 || ^11.5 || ^12.1
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform