Package Health

ad3n/ratchet-bundle

The repository has no tests or security scanning, and its small community offers little evidence of support. The MIT license and clear README improve transparency but do not offset the maintenance concerns.

Latest v0.6PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was in June 2020, with no releases in the last 12 months. This long pause is substantial abandonment evidence, although the repository remains available.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last 3 months, consistent with the package's prolonged release gap. The repository was pushed more recently than the latest release, but current activity is still absent.

Repo popularitycaution

The repository has only 11 stars, 1 fork, and 1 watcher, providing limited supporting evidence of a broad user or maintainer community.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. That leaves an avoidable gap in the project's maintenance controls.

Security policycaution

The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a hygiene and maintenance concern rather than evidence of malicious behavior.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Muhammad Surya Ihsanuddin

Direct Dependencies

DependencyLast ReleaseScore
cboden/ratchet
Version ^0.4
—
—
symfony/config
Version ~3.0|~4.0|~5.0
—
—
symfony/console
Version ~3.0|~4.0|~5.0
—
—
symfony/http-kernel
Version ~3.0|~4.0|~5.0
—
—
symfony/framework-bundle
Version ~3.0|~4.0|~5.0
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform