Package Health

typo3/cms-reports

This is a mature, actively released TYPO3 extension with a long release history, stable versioning, current publication activity, an unarchived organization-owned repository, and three active contributors in the last three months. The artifact is licensed, has a coherent 60-file implementation and documentation tree, uses no install-time lifecycle scripts, and has a narrow runtime dependency profile. The main reservations are the absence of a repository security policy and security-scanning tooling, limited recent commit volume, no recent issue or pull-request activity, and no changelog; however, repository tests compensate for the artifact's missing packaged tests, and the organization backing reduces concern from the single registry maintainer and concentrated commit share.

Latest v14.3.7PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The artifact includes a README but no packaged tests or changelog; the linked repository does contain tests, which compensates for the missing packaged tests, while the absent changelog is a modest documentation gap.

Repo bus factorcaution

The top contributor made about 71% of the seven recent commits, which indicates concentration; however, two additional contributors remained active and the repository is organization-owned, providing some handoff capacity.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, and issue counts are unavailable. This leaves recent community activity unverified and is a modest maintenance-signal gap, though it is outweighed by the active release history and recent commits.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanning coverage is a transparency and assurance gap, not a standalone health verdict.

Security policycaution

The linked repository has no security policy, reducing transparency around vulnerability reporting and response expectations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

TYPO3 Core Team

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version 14.3.7
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform