Package Health

syntro/silverstripe-elemental-elementals

The package is licensed, documented, tested, and backed by an organization. Composer tooling, Dependabot, and a clean workflow audit provide useful maintenance safeguards, though one workflow action is unpinned.

Latest 1.0.1PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

Only two releases were published, with the latest on September 1, 2022 and none in the last 12 months. This is a substantial maintenance concern for a package released over four years ago.

Repo commit activitycaution

There were no commits and no active maintainers in the three months measured. This weakens the evidence of ongoing maintenance, although the repository's recent push provides some compensating evidence.

Security policycaution

No security policy is present. This is a transparency gap, though the package's small, documented repository and Dependabot coverage partly reduce its significance.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Its one action is unpinned, a minor reproducibility and supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Matthias Leutenegger

Direct Dependencies

DependencyLast ReleaseScore
silverstripe/cms
Version ^4
—
—
silverstripe/framework
Version ^4
—
—
unclecheese/display-logic
Version ^2
—
—
gorriecoe/silverstripe-link
Version ^1
—
—
dnadesign/silverstripe-elemental
Version ^4
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform