Package Health

atolye15/contentful-bundle

The package is clearly documented, tested, licensed, and not deprecated or archived. Its release and commit activity stopped in April 2020, while the repository has no security policy, leaving maintenance and vulnerability-response risk.

Latest 4.1.2PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was published in April 2020, with no releases in the last 12 months and only 11 releases overall. This strongly suggests the package is no longer maintained, despite its stable version history.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months, consistent with the last push in April 2020. This leaves current maintenance and compatibility fixes unlikely.

Repo popularitycaution

The repository has one star, no forks, and no watchers. Low popularity is only supporting evidence, but it provides little external evidence of ongoing use or review.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected. The missing scanning is a hygiene gap, while the long period without activity is the larger concern.

Security policycaution

The repository has no security policy, so it gives users no documented path for reporting vulnerabilities or understanding response expectations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
atolye15/contentful
Version 4.2.*
—
—
symfony/framework-bundle
Version ^3.4|^4.0
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform