Package Health

typo3/coding-standards

The package is clearly documented and its release includes notes backed by repository tests. Maintenance is active and organization-backed, though recent work is concentrated in one contributor and all 18 workflow actions are unpinned.

Latest v0.9.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo bus factorcaution

All 8 recent commits came from one contributor, creating concentration risk. Organization ownership provides some handoff capacity, so this is a caution rather than a severe abandonment signal.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. For a coding-standards package this is a modest transparency gap, not evidence of unsafe behavior.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a maintenance and transparency gap, but the organization-backed repository partly reduces the concern.

Version stabilitycaution

Version 0.9.0 is not a stable major release, which signals some API maturity uncertainty, but it is not marked as a prerelease and has no recent prerelease pattern.

Workflow auditcaution

Both workflows were analyzed cleanly and no audit findings or untrusted checkout sinks were reported. However, all 18 action references are unpinned, weakening build reproducibility and update safety.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Benni Mack
Simon Gilli

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^6.4 || ^7.4 || ^8.0
symfony/filesystem
Version ^6.4 || ^7.4 || ^8.0
friendsofphp/php-cs-fixer
Version ^3.95.1

Weekly Downloads

Info

Last Published
1 month ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform