Package Health

2lenet/entity-file-bundle

This is a generally usable and reasonably mature release: it has been published for over four years, has 15 releases including 6 in the last 12 months, is stable, non-deprecated, licensed, documented, and backed by an active non-archived organization repository with tests and CI workflows. The main concern is maintenance momentum: the repository recorded no commits and no active maintainers in the last 3 months, while issue activity is minimal and the project has only 3 stars. Missing security scanning, security policy documentation, and explicit workflow token permissions add transparency and CI-hardening gaps, but the repository remains maintained enough overall to support a cautious dependency decision.

Latest 1.2.5PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

Seven runtime dependencies, including framework, ORM, filesystem, and form components, create meaningful transitive maintenance surface for a bundle of this scope, though the profile is not unusually large.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, a concrete sign of currently stalled maintenance despite the recent registry release history.

Repo issue activitycaution

There are no open issues and one open pull request, but no issues or pull requests were merged in the last month, providing little evidence of active community maintenance.

Repo popularitycaution

The repository has only 3 stars, 1 fork, and 1 watcher, indicating limited external adoption and community redundancy; popularity is supporting evidence, so this is a caution rather than a decisive health failure.

Repo toolingcaution

The project uses Make and Composer and has build tooling, but no security scanning tools are configured, leaving a security-process gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

2LE

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^2.12 || ^3.0
—
—
symfony/form
Version ^7.0 || ^8.0
—
—
league/flysystem-bundle
Version ^3.0
—
—
doctrine/doctrine-bundle
Version ^2.6 || ^3.0
—
—
gedmo/doctrine-extensions
Version ^3.7
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform