Package Health

terminal42/contao-countryselect

The organization-backed repository matches the package and has a clear MIT license and readme. One contributor made only one recent commit, while the workflow uses an unpinned action and has no security policy.

Latest 1.5.5PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The latest registry release was published over three years ago, and there were no releases in the last 12 months. Recent repository activity partly offsets the concern, but the shipped release cadence remains stale.

Repo bus factorcaution

All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.

Repo commit activitycaution

The repository recorded only one commit in the last three months from one active maintainer. This shows some maintenance, but limited recent activity lowers confidence in ongoing release support.

Security policycaution

The repository has no published security policy. This is a transparency and issue-handling gap, though it is not evidence of a security incident.

Workflow auditcaution

The workflow is fully analyzed, uses read-only permissions, and has no audited findings, but its only action reference is unpinned. That leaves avoidable build-integrity exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

terminal42 gmbh

Direct Dependencies

DependencyLast ReleaseScore
contao/core-bundle
Version ^4.13 || ^5.0
—
—
symfony/polyfill-php80
Version *
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform