Package Health

starterteam/starter-nessa

This release appears actively maintained and generally suitable to depend on: it has 20 releases over roughly 4.6 years, 10 releases in the last 12 months, a stable non-prerelease version, recent repository activity, automated build and dependency tooling, repository tests, and no deprecation or archival status. The main risks are a proprietary license, complete concentration of recent commits in one contributor, limited artifact documentation, absent security policy, and a release workflow with top-level write permissions. These concerns warrant review of licensing and continuity before adoption, but the maintenance and release evidence outweighs them.

Latest v14.4.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Licensedanger

The package declares a proprietary license in its manifest and has no license file. This is a material adoption and redistribution constraint rather than an open-source transparency strength.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational handoff capacity to offset the concentrated contributor base.

Repo bus factorcaution

All 39 commits in the last 3 months came from one contributor, giving a 100% top-contributor share. This creates a genuine continuity risk for an individually owned project.

Repo popularitycaution

The repository has zero stars and forks and one watcher. This provides little external adoption evidence, but popularity is supporting evidence and does not outweigh the strong release and commit activity.

Security policycaution

No repository security policy was found. This weakens vulnerability-reporting transparency, although it is a hygiene gap rather than evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marcel Schmid
Christian Wolfram

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^13.4 || ^14.3
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform