Package Health

svewap/a21glossary

The source repository remains active under an organization, but activity is minimal and concentrated in one contributor. Open work is not moving, and the project lacks a security policy and pins none of its workflow actions.

Latest 13.0.0PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

25

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names wapplersystems/a21glossary as its replacement. This is a severe adoption risk for a new dependency.

Release historycaution

The package has had no releases in the last 12 months, despite 10 releases overall. The repository's later push provides some evidence of ongoing work, but does not offset the missing release cadence.

Repo bus factorcaution

All recent commits come from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown in this period.

Repo commit activitycaution

Only 1 commit was recorded in the last 3 months, from 1 active maintainer. This indicates very limited recent maintenance capacity.

Repo issue activitycaution

The repository has 12 open issues and 7 open pull requests, with no new or closed items in the last month. That combination suggests unresolved maintenance backlog.

Vulnerabilities

TitleVersionsSeverity
CVE-2009-4803
svewap/a21glossary is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 0.4.10.
0.0.0 - 0.4.10
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^13.4.0
—
—
typo3/cms-frontend
Version ^13.4.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform