Package Health

wazum/sluggi

The single-contributor base and fully unpinned GitHub Actions leave maintenance continuity and build reproducibility weaker than ideal. A missing security policy is a smaller transparency gap; the package otherwise has useful documentation and release notes.

Latest 14.15.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Project backingcaution

The registry namespace and repository are owned by the same individual account, so there is no demonstrated organization backing to offset the concentrated contributor base.

Repo bus factorcaution

One contributor made 100% of the 81 recent commits, leaving maintenance continuity dependent on a single person and increasing abandonment risk if they become unavailable.

Security policycaution

The repository has no security policy, making vulnerability reporting and response expectations less transparent for consumers.

Workflow auditcaution

All 5 workflows were analyzed successfully with no high-confidence audit findings or untrusted execution sinks. However, all 31 action references are unpinned, and two workflows grant top-level write permissions, creating reproducibility and least-privilege concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Wolfgang Klinger

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^12.4 || ^13.4.26 || ^14.3
typo3/cms-backend
Version ^12.4 || ^13.4.26 || ^14.3
typo3/cms-redirects
Version ^12.4 || ^13.4.26 || ^14.3

Weekly Downloads

Info

Last Published
5 hours ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform