Package Health

zaita/sdlt-framework

The repository is not archived and includes tests, a README, and a matching BSD-3-Clause license. It lacks security scanning and a security policy, while install and update hooks add operational review work.

Latest 5.0.6PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months. Combined with no registry releases in over two years, this indicates a substantial risk of slowed maintenance.

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These are not inherently unsafe, but they increase installation and upgrade behavior that dependents must account for.

Release historycaution

The package has 22 releases, but the latest was over two years ago and there were no releases in the last 12 months. That is a meaningful maintenance concern for a framework dependency.

Repo toolingcaution

Composer build tooling is present, but no repository security-scanning tools were detected. That is a hygiene gap for a framework containing substantial application and integration code.

Security policycaution

The repository has no security policy. This weakens vulnerability-reporting transparency, though it is not by itself evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^3.8
—
—
swaggest/json-schema
Version ^0.12.24
—
—
ergebnis/json-printer
Version ^3.0
—
—
silverstripe/crontask
Version ^2.0
—
—
silverstripe/recipe-cms
Version ^4.13.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform