Package Health

2lenet/config-bundle

Regular releases and a clear README make adoption easier. Organization backing helps offset the narrow recent contributor base, while workflow references are not pinned.

Latest 1.5.3PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo bus factorcaution

One contributor made 100% of the six recent commits. The organization-owned project provides some handoff capacity, but recent maintenance remains highly concentrated.

Repo commit activitycaution

Six commits were made in the last 3 months, showing current activity. However, all activity came from one active maintainer, limiting resilience if that person stops contributing.

Repo toolingcaution

Composer build tooling is present, but no security scanning tooling was detected. This is a modest transparency and assurance gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy. For a maintained library this reduces clarity about vulnerability reporting and response expectations.

Workflow auditcaution

All three workflows were analyzed successfully with no high-confidence audit findings or untrusted checkouts. However, all 9 action references are unpinned, leaving build inputs less reproducible; the lack of top-level permissions is acceptable on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

2LE Team

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.4 || ^4.0
—
—
doctrine/orm
Version ^2.6,>=2.6.3 || ^3.0
—
—
2lenet/crudit-bundle
Version ^1.12
—
—
doctrine/persistence
Version ^2.0 || ^3.0 || ^4.0
—
—
doctrine/doctrine-bundle
Version ^2.0 || ^3.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform