Package Health

3slab/vdm-library-doctrine-odm-transport-bundle

Tests, a license file, and no install-time scripts provide useful baseline safeguards. The beta status, almost six years without a release, and no recent commits make this a poor choice for a new dependency.

Latest 2.0.0-beta2PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

58

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historydanger

Only two releases exist, with none in the last 12 months; the latest release was in December 2020, almost six years before collection. This is strong evidence of abandonment risk.

Repo commit activitydanger

The repository had zero commits and zero active maintainers in the last three months. Combined with the stale release history, this indicates no current maintenance activity.

Licensecaution

A LICENSE file is present and identifies MIT, but the manifest declares the package proprietary. This mismatch creates avoidable licensing uncertainty despite the available license text.

Repo toolingcaution

Composer is used for the build, but no security-scanning tooling was detected. The missing scanner is a hygiene weakness, not by itself evidence that the package is unsafe to depend on.

Version stabilitycaution

The assessed version is a prerelease beta, and all recent releases are prereleases. That leaves the package without a demonstrated stable release line.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jonathan Bouzekri
Julian Marié

Direct Dependencies

DependencyLast ReleaseScore
doctrine/mongodb-odm
Version ^2.0.5
3slab/vdm-library-bundle
Version ^2.0@beta
doctrine/mongodb-odm-bundle
Version ^4.1

Weekly Downloads

Info

Last Published
5 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform