Package Health

useburrow/craft-burrow

This is a relatively young but actively maintained Craft CMS plugin with 30 releases over 168 days, a stable current major version, a non-deprecated registry status, and a recently updated repository. The organization-owned repository matches the package and references it in its README, and two contributors have been active recently, although 84% of the last three months' commits came from one contributor. The package has a clear README, changelog, license file, and conventional Composer build setup, but it lacks tests, repository security scanning, and a security policy. Overall, it appears usable to depend on, with moderate maintenance and transparency risks that warrant normal due diligence for a package handling integrations and operational data.

Latest 5.5.4PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The artifact has a substantial README of 9,461 characters and a changelog, while neither the package nor repository contains tests. Documentation and release notes are positive, but the absence of tests is a genuine quality and maintenance gap for an integration-heavy plugin.

Repo bus factorcaution

Two contributors were active, but the leading contributor made 84% of recent commits. The second contributor provides some redundancy, while the organization backing reduces the risk of total single-person dependence; concentration remains a moderate caution.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently negative for a young, actively released project, but it provides little evidence of public maintenance interaction.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This limits external validation and adoption evidence, but popularity is supporting evidence and the package has direct activity signals, so this is only a mild concern.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools were detected. The conventional build setup is positive, while the missing automated security tooling leaves a transparency and assurance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Burrow Analytics, LLC

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^5.0
useburrow/sdk-php
Version ^0.9.9

Weekly Downloads

Info

Last Published
17 days ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform