Package Health

atoolo/translator-bundle

The repository does not clearly identify the package in its name or README, and all three workflow action references are unpinned. Tests, a changelog, release notes, MIT licensing, Dependabot, and organizational backing provide useful counterweight.

Latest 1.0.0PackagistPackagist

56%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-install command, which adds install-time behavior that consumers must account for. No other provided signal shows that this script is harmful or unusually broad, so the effect is limited to a review concern.

Release historycaution

This is the only release, published 550 days ago, with no releases in the last 12 months. A single stable release can be intentional, but the lack of follow-up evidence raises maintenance risk.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long period since its initial release. This weakens confidence that defects or dependency changes will be addressed promptly.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, making package-to-source ownership less transparent. Organizational backing and the matching repository URL partly reduce, but do not remove, that concern.

Workflow auditcaution

All three analyzed action references are unpinned, which leaves workflow dependencies exposed to changing upstream code. The audit found no dangerous triggers, untrusted checkouts, script injection, or other reported findings, so this is a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

veltrup

Direct Dependencies

DependencyLast ReleaseScore
nyholm/psr7
Version ^1.8
symfony/yaml
Version ^6.3 || ^7.0
symfony/cache
Version ^6.3 || ^7.0
symfony/config
Version ^6.3 || ^7.0
symfony/console
Version ^6.3 || ^7.0

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform